Vulnerability Description
The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/devs-crm/v1/bulk-update' REST-API endpoint in all versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to update leads tags.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/devs-crm/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/78794ea4-6eff-4e6f-af0
FAQ
What is CVE-2025-13093?
CVE-2025-13093 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/devs-crm/v1/bu...
How severe is CVE-2025-13093?
CVE-2025-13093 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13093?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.