CVE-2025-13092 | Devs CRM Plugin up to 1.1.8 on WordPress REST API Endpoint attendances weak password hash (EUVD-2025-203204)
A vulnerability was found in Devs CRM Plugin up to 1.1.8 on WordPress. It has been declared as problematic. Affected is an unknown function of the file /wp-json/devs-crm/v1/attendances of the component REST API Endpoint. The manipulation results in password hash with insufficient computational effort.
This vulnerability was named CVE-2025-13092. The attack may be performed from remote. There is no available exploit.