W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory, and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected products
1- Range: <=2.2.0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Authdata.phpmitre
- plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Authdata.phpmitre
- plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Setting.phpmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/b99ba627-1d24-4be1-a4db-ff39354526f2mitre
News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)Wordfence Blog · Jul 23, 2026