
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13092 is a missing authorization vulnerability in the Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress. It affects all versions up to and including 1.1.8, allowing unauthenticated attackers to access the /wp-json/devs-crm/v1/attendances REST API endpoint without any capability check. This exposes private user data, including password hashes, to any network-accessible attacker. It carries a CVSS v3.1 base score of 5.3 (Medium) and was published on December 13, 2025 (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin's REST API endpoint /wp-json/devs-crm/v1/attendances does not enforce any WordPress capability or permission check before returning data. Because the endpoint is registered without authentication requirements, any unauthenticated HTTP GET request to the endpoint can retrieve sensitive records. No special preconditions, credentials, or user interaction are required; the attacker only needs network access to the WordPress installation (Wordfence, ENISA EUVD).
Successful exploitation allows unauthenticated remote attackers to retrieve private user data stored by the Devs CRM plugin, most critically including WordPress password hashes. Exposure of password hashes enables offline cracking attacks, which could lead to account takeover of WordPress users — including administrators — and potential full site compromise. There is no integrity or availability impact, but the confidentiality breach can serve as a stepping stone for broader lateral movement within the WordPress environment (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13092 as of the available data. The EPSS score is approximately 0.035%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial exploitation mechanics — a simple unauthenticated HTTP request — mean the barrier to exploitation is extremely low for any attacker who identifies a vulnerable installation (Wordfence, ENISA EUVD).
/wp-content/plugins/devs-crm/ for plugin presence.GET https://<target>/wp-json/devs-crm/v1/attendances/wp-json/devs-crm/v1/attendances from external or unexpected IP addresses; high-frequency requests to this endpoint suggesting automated scanning.access.log) showing GET /wp-json/devs-crm/v1/attendances with HTTP 200 responses from unauthenticated sessions (no Authorization header or valid nonce); repeated requests from the same IP or user-agent string./wp-content/plugins/devs-crm/.The primary remediation is to update the Devs CRM plugin to a version beyond 1.1.8 that includes a proper capability check on the REST API endpoint. Site administrators should check the WordPress plugin page for the latest patched release. As an immediate workaround, if no patch is available or the plugin is not actively needed, deactivate or remove the plugin entirely. Additionally, administrators should audit user accounts for signs of unauthorized access and consider forcing a password reset for all users, as hashes may have already been exposed (Wordfence, WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."