Junglewise Threat Intelligence

CVE-2026-9004: WP-CRM System plugin sensitive information exposure via contact_id enumeration

CVE-2026-9004 · Severity: medium · CVSS 4.3 · Published 2026-09-22

Executive brief

The WP-CRM System plugin for WordPress, used to manage client and project data, exposes sensitive contact information including names, email addresses, phone numbers, and physical addresses. An attacker with contributor-level access or higher can retrieve this data by manipulating the contact_id parameter to enumerate arbitrary contact records.

Technical details

The vulnerability is an information disclosure flaw in the WP-CRM System plugin affecting versions up to 3.4.6. Authenticated attackers with contributor-level privileges can extract full contact records via parameter enumeration of the contact_id field. The attack requires authentication but no user interaction beyond making requests.

Affected products

  • WP-CRM System WP-CRM System – Manage Clients and Projects up to 3.4.6

Timeline

  • 2026-09-22: disclosed

References