What the vulnerability does
01Description
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
Explanation of Vulnerability in Simple Terms
The Zoho CRM Lead Magnet WordPress plugin version 1.7.5.8 and earlier contains an authorization flaw that allows authenticated users with low privileges to read, modify, or delete sensitive data and configuration. An attacker with a standard user account can escalate their access to perform actions restricted to administrators, potentially compromising the entire CRM integration and customer data stored through the plugin.
What an attacker can do
Read, modify, or delete CRM data and plugin settings with a low-privilege user account.
Potential impact on your site
Customer data in Zoho CRM and plugin configuration can be accessed or altered by any logged-in user, not just administrators.
Conditions required to exploit
Attacker needs a valid WordPress user account with low privileges (subscriber or contributor level).
Key dates
External resources
Related vulnerabilities