Executive brief
The WP-CRM System plugin for WordPress, used to manage client and project data, exposes sensitive contact information including names, email addresses, phone numbers, and physical addresses. An attacker with contributor-level access or higher can retrieve this data by manipulating the contact_id parameter to enumerate arbitrary contact records.
Technical details
The vulnerability is an information disclosure flaw in the WP-CRM System plugin affecting versions up to 3.4.6. Authenticated attackers with contributor-level privileges can extract full contact records via parameter enumeration of the contact_id field. The attack requires authentication but no user interaction beyond making requests.
Affected products
- WP-CRM System WP-CRM System – Manage Clients and Projects up to 3.4.6
Timeline
- 2026-09-22: disclosed