CVE-2025-5692 Details
Description
The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform several actions like updating settings. Initially this CVE was assigned specifically to all AJAX actions and the doFieldAjaxAction() function, however it was determined that CVE-2025-47690 is assigned to the doFieldAjaxAction() function that leads to arbitrary options updates.
A vulnerability in the Lead Form Data Collection to CRM plugin for WordPress, affecting versions through 3.1, allows authenticated users with Subscriber-level access and above to bypass authorization and modify arbitrary data. The issue arises from a missing capability check in the 'doFieldAjaxAction()' function, enabling unauthorized changes to WordPress options. This vulnerability can be exploited to elevate the default user role for new registrations to administrator, potentially granting administrative access to the site. Additionally, other AJAX actions related to plugin settings are similarly vulnerable.
Users are advised to update the plugin to version 3.2 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| smackcoders lead form data collection to crm | < 3.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | Modified Analysis | [email protected] |
| Aug 27, 2025 | CVE Modified | [email protected] |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| Jul 2, 2025 | New CVE Received | [email protected] |