AMO.CRM WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the AMO.CRM integration WordPress plugin, affecting all versions up to and including 1.0.1. The vulnerability arises from inadequate nonce validation in the 'settings_page' function, allowing unauthenticated attackers to alter essential API connection settings. This includes the AMO.CRM API URL, login credentials, and API hash key, by sending a forged request that tricks a site administrator into clicking a link.

Impact

Exploitation allows for unauthorized modification of API connection settings, potentially leading to unauthorized access or actions within the AMO.CRM integration.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Sep 11, 2025, 8:51 AM
Updated: Sep 11, 2025, 8:51 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.0
remediation
0.0
relevance
0.5
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.