CVE-2025-47690: WordPress Lead Form Data Collection to CRM plugin <= 3.1 - Arbitrary Option Update to Privilege Escalation vulnerability
Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1.
Other sources
Missing Authorization vulnerability in smackcoders Lead Form Data Collection to CRM allows Privilege Escalation. This issue affects Lead Form Data Collection to CRM: from n/a through 3.1.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47690?
CVE-2025-47690 has a high severity due to its potential for privilege escalation.
How do I fix CVE-2025-47690?
To fix CVE-2025-47690, update the Smackcoders Lead Form Data Collection to CRM plugin to version 3.2 or later.
What versions are affected by CVE-2025-47690?
CVE-2025-47690 affects versions of Smackcoders Lead Form Data Collection to CRM up to and including 3.1.
Who is impacted by CVE-2025-47690?
Users of the Smackcoders Lead Form Data Collection to CRM and WordPress Lead Form Data Collection to CRM plugins are impacted by CVE-2025-47690.
Is CVE-2025-47690 a code injection vulnerability?
No, CVE-2025-47690 is a missing authorization vulnerability, allowing privilege escalation rather than a code injection.