PT-2026-60920 · WordPress · Elementor To Zoho Crm

·

CVE-2026-9734

·

Published

2026-07-18

·

Updated

2026-07-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions W3SC Elementor to Zoho CRM versions prior to 2.2.1
Description The plugin is subject to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a victim into performing actions they did not intend to do. This occurs due to missing or incorrect nonce validation in the storeInfo() function. Unauthenticated attackers can exploit this to modify Zoho CRM integration settings by replacing the data center, client ID, client secret, and user email credentials with values controlled by the attacker, provided they can trick a site administrator into clicking a malicious link.
Recommendations Update the plugin to a version newer than 2.2.0. As a temporary mitigation, restrict access to the plugin settings to only trusted administrators.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9734

Affected Products

Elementor To Zoho Crm