CVE-2026-9004 | nofearinc WP-CRM System Plugin up to 3.4.6 on WordPress contact_id information disclosure
A vulnerability, which was classified as problematic, has been found in nofearinc WP-CRM System Plugin up to 3.4.6 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument contact_id results in information disclosure.
This vulnerability is identified as CVE-2026-9004. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More