Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

crmperks — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting crmperks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CRMperks is a WordPress plugin designed to manage customer relationships and integrate CRM systems. Historically, the plugin has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. With 14 CVEs recorded, CRMperks has faced repeated security incidents, including cases where attackers could execute arbitrary code or steal sensitive data. The plugin's vulnerabilities have primarily affected WordPress sites, allowing unauthorized access or system compromise. Security researchers have consistently identified similar patterns in the codebase, highlighting ongoing security challenges in the plugin's design and implementation.

Found 7 results / 14Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-3831 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode — Database for Contact Form 7, WPforms, Elementor formsCWE-862 4.3 Medium2026-04-01
CVE-2026-2599 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv' — Database for Contact Form 7, WPforms, Elementor formsCWE-502 9.8 Critical2026-03-05
CVE-2026-0825 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export — Database for Contact Form 7, WPforms, Elementor formsCWE-862 5.3 Medium2026-01-28
CVE-2025-7384 Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion — Database for Contact Form 7, WPforms, Elementor formsCWE-502 9.8 Critical2025-08-13
CVE-2024-3715 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting — Database for Contact Form 7, WPforms, Elementor formsCWE-79 7.2 High2024-05-02
CVE-2024-2030 Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode — Database for Contact Form 7, WPforms, Elementor formsCWE-79 6.4 Medium2024-03-13
CVE-2024-1069 Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload — Database for Contact Form 7, WPforms, Elementor formsCWE-434 7.2 High2024-01-31

This page lists every published CVE security advisory associated with crmperks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.