Missing Authorization in WP-CRM System by Mario Peshev
CVE-2025-62740
5.3MEDIUM
What is CVE-2025-62740?
The WP-CRM System plugin by Mario Peshev is vulnerable to missing authorization due to improperly configured access control security levels. This flaw can be exploited by unauthorized users, allowing them to gain access to sensitive data and functionality. The vulnerability impacts versions up to and including 3.4.5, underscoring the importance of updating to ensure robust security practices.
Affected Version(s)
WP-CRM System 0 <= 3.4.6