CVE-2026-9004: Nofearinc Wp-CRM System – Manage Clients And Projects
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract full names, email addresses, phone numbers, mobile numbers, fax numbers, and physical address information of arbitrary CRM contact records by enumerating the contact_id parameter.
Affected products
- Nofearinc Wp-CRM System – Manage Clients And Projects: up to and including 3.4.6
Published 2026-09-22. Last modified 2026-09-22.