Medium severity5.4NVD Advisory· Published Jan 14, 2026· Updated Apr 15, 2026
CVE-2025-14854
CVE-2025-14854
Description
The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status AJAX functions in all versions up to, and including, 3.4.5. This makes it possible for authenticated attackers, with subscriber level access and above, to enumerate CRM contact email addresses (PII disclosure) and modify CRM task statuses. CVE-2025-62106 is likely a duplicate of this issue.
Affected products
2- Range: <=3.4.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/wp-crm-system/tags/3.4.5/includes/wcs-dashboard-task-list.phpnvd
- plugins.trac.wordpress.org/browser/wp-crm-system/tags/3.4.5/includes/wcs-functions.phpnvd
- plugins.trac.wordpress.org/browser/wp-crm-system/tags/3.4.6/includes/wcs-functions.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/da607df4-1dbb-4b1e-ace6-b339cf9e8512nvd
News mentions
0No linked articles in our index yet.