Junglewise Threat Intelligence

CVE-2026-9734: W3SC Elementor to Zoho CRM CSRF in storeInfo function

CVE-2026-9734 · Severity: medium · CVSS 4.3 · Published 2026-07-18

Executive brief

The W3SC Elementor to Zoho CRM plugin for WordPress, which connects website forms to Zoho's customer management system, contains a security flaw that could allow an attacker to hijack the connection. By tricking a site administrator into clicking a malicious link, an attacker can change the plugin's settings to use their own Zoho account credentials. This could result in customer data being sent to an attacker-controlled database instead of the intended business account.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the W3SC Elementor to Zoho CRM plugin for WordPress due to missing or insufficient nonce validation in the storeInfo function. The affected components include Authdata.php and Setting.php within the administrative interface. An unauthenticated attacker can exploit this by inducing a logged-in administrator to submit a specially crafted web request, typically via social engineering or a malicious link. Successful exploitation allows the attacker to overwrite critical Zoho CRM integration parameters, including the Client ID, Client Secret, and data center location. This vulnerability affects all versions of the plugin up to and including 2.2.0.

Affected products

  • w3scloud W3SC Elementor to Zoho CRM <= 2.2.0

Timeline

  • 2026-07-18: disclosed: Initial publication of the vulnerability advisory.

References