Executive brief
The Catalyst Connect Zoho CRM Client Portal plugin for WordPress, which integrates Zoho CRM data into WordPress sites, contains a security flaw that allows administrators to perform unauthorized database queries. By exploiting this vulnerability, a high-privileged user could extract sensitive information from the website's database that they might not otherwise have access to. The plugin has been temporarily closed for download while these issues are reviewed.
Technical details
A time-based SQL injection vulnerability exists in the Catalyst Connect Zoho CRM Client Portal plugin due to insufficient escaping and lack of query preparation on the 'uid' parameter. The flaw is located in the header.php file within the pages/admin/usersManagement/details path, where the GET parameter is directly concatenated into a SQL statement. An authenticated attacker with Administrator-level privileges can exploit this via the 'userdetails' action in the 'usersmanagement' page to execute arbitrary SQL commands. This allows for the extraction of sensitive data from the WordPress database. The plugin was temporarily closed on the WordPress repository as of June 29, 2026.
Affected products
- Catalyst Connect Catalyst Connect Zoho CRM Client Portal up to, and including, 2.2.0
Timeline
- 2026-06-29: other: Plugin temporarily closed on WordPress.org repository
- 2026-07-11: advisory: CVE published by Wordfence/NVD