CVE-2025-13093 | Devs CRM Plugin up to 1.1.8 on WordPress API Endpoint bulk-update authorization
A vulnerability classified as problematic has been found in Devs CRM Plugin up to 1.1.8 on WordPress. The affected element is an unknown function of the file /wp-json/devs-crm/v1/bulk-update of the component API Endpoint. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2025-13093. Remote exploitation of the attack is possible. No exploit is available.