Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ajitdas
Ajitdas devs Crm Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ajitdas
Ajitdas devs Crm Wordpress Wordpress wordpress |
Sat, 13 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/devs-crm/v1/attendances REST API Endpoint in all versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to retrieve private user data, including password hashes. | |
| Title | Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Unauthenticated Information Expsoure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:21:11.739Z
Reserved: 2025-11-12T20:40:30.930Z
Link: CVE-2025-13092
Updated: 2025-12-15T15:24:57.061Z
Status : Deferred
Published: 2025-12-13T16:16:46.993
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13092
No data.
OpenCVE Enrichment
Updated: 2026-04-21T17:15:25Z