Devs CRM WordPress Plugin Unauthenticated Data Exposure Vulnerability
Vulnerability
A vulnerability exists in the Devs CRM WordPress plugin, specifically in versions through 1.1.8, allowing unauthorized access to private user data. This issue arises from a missing capability check on the /wp-json/devs-crm/v1/attendances REST API endpoint, enabling unauthenticated attackers to retrieve sensitive information, including password hashes.
Impact
Exploitation of this vulnerability could lead to unauthorized access to private user data, including password hashes.
Added: Dec 13, 2025, 5:17 PM
Updated: Dec 13, 2025, 5:17 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
1.4threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
