CVE-2026-9004
Received Received - Intake

Sensitive Information Exposure in WP-CRM System WordPress Plugin

Vulnerability report for CVE-2026-9004, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Wordfence

Description

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract full names, email addresses, phone numbers, mobile numbers, fax numbers, and physical address information of arbitrary CRM contact records by enumerating the contact_id parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp-crm_system manage_clients_and_projects to 3.4.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the WP-CRM System plugin for WordPress allows authenticated attackers with contributor-level access or higher to expose sensitive personal data by manipulating the 'contact_id' parameter. The flaw enables extraction of full names, email addresses, phone numbers, and physical addresses from CRM contact records.

Detection Guidance

To detect this vulnerability, monitor WordPress sites using the WP-CRM System plugin for unusual requests to the contact_id parameter. Check server logs for repeated access attempts to /wp-json/wp-crm/v1/contacts/ with varying contact_id values. Use tools like grep to search logs for patterns like 'contact_id='.

Impact Analysis

If you use this WordPress plugin, attackers could access private customer data including contact details. This could lead to privacy breaches, identity theft risks for your users, and potential misuse of exposed information.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and potential failure to protect user information. It may also impact HIPAA compliance if healthcare-related contact data is exposed, as it demonstrates inadequate safeguards for protected health information.

Mitigation Strategies

Immediately update the WP-CRM System plugin to the latest version if available. If no update exists, consider disabling the plugin temporarily or restricting access to authenticated users with contributor-level permissions or higher. Review server logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9004. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart