CVE-2025-10746 🟡 Medium

CVE-2025-10746: Unauthorized Access in Integrate Dynamics 365 CRM Plugin

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access due to missing checks in version 1.0.9 and below.

CVE ID

CVE-2025-10746

CVSS Score

6.5

Vendor

unknown

Published

Oct 04

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to missing capability checks and nonce verification on functions hooked to 'init'. This makes it possible for unauthenticated attackers to deactivate the plugin, tamper with OAuth configuration, and trigger test connections that expose sensitive data via direct requests to vulnerable endpoints if they can craft malicious requests with specific parameters.

Vulnerability Details

CVE ID
CVE-2025-10746
Severity
Medium
CVSS v3 Score
6.5 / 10.0
Affected Vendor
unknown
Publication Date
October 04, 2025

Need Help?

Protect your infrastructure with our comprehensive security scanning tools.

Explore Security Scanners