
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62106 is a Missing Authorization vulnerability in the WP-CRM System WordPress plugin developed by Mario Peshev. It allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels, potentially performing unauthorized actions on affected systems. The vulnerability affects WP-CRM System versions up to and including 3.4.5. It was published on January 22, 2026, by Patchstack. The CNA (Patchstack) assigned a CVSS v3.1 base score of 5.4 (Medium), while CISA-ADP initially scored it 8.8 (High) before the Patchstack score superseded it (NVD, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive operations. This allows a low-privileged authenticated user to access or manipulate functionality that should be restricted to higher-privileged roles. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid WordPress account (NVD, Patchstack).
Successful exploitation allows an authenticated low-privilege attacker to perform unauthorized actions within the WP-CRM System plugin, potentially accessing sensitive CRM data (customer records, contact information), modifying or deleting records, and disrupting plugin operations. The Patchstack-assigned score reflects limited confidentiality and integrity impact (C:L/I:L/A:N), suggesting the practical impact may be constrained to plugin-level data rather than full system compromise. However, exposure of CRM data could facilitate further social engineering or targeted attacks (NVD).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (NVD, Patchstack).
Users should update the WP-CRM System plugin to a version newer than 3.4.5 as soon as a patched release becomes available. In the interim, site administrators should review and restrict user role assignments within WordPress, applying the principle of least privilege to limit which accounts can interact with the WP-CRM System plugin. If no patch is available and the risk is unacceptable, consider temporarily deactivating the plugin. Monitor WordPress and plugin access logs for unusual activity from low-privileged accounts (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."