Devs CRM WordPress Plugin Unauthenticated Data Exposure Vulnerability

Vulnerability

A vulnerability exists in the Devs CRM WordPress plugin, specifically in versions through 1.1.8, allowing unauthorized access to private user data. This issue arises from a missing capability check on the /wp-json/devs-crm/v1/attendances REST API endpoint, enabling unauthenticated attackers to retrieve sensitive information, including password hashes.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private user data, including password hashes.

Added: Dec 13, 2025, 5:17 PM
Updated: Dec 13, 2025, 5:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.