CRM and Lead Management by vcita Security & Risk Analysis

wordpress.org/plugins/crm-customer-relationship-management-by-vcita

CRM for WordPress: a powerful, all-in-one client management tool that will help you keep your clients close and create long-lasting customer relations …

100 active installs v2.8.1 PHP + WP 4.6+ Updated Jul 23, 2025
contactcrmdatabaseleadsmanagement
96
A · Safe
CVEs total5
Unpatched0
Last CVEJul 21, 2025
Safety Verdict

Is CRM and Lead Management by vcita Safe to Use in 2026?

Generally Safe

Score 96/100

CRM and Lead Management by vcita has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jul 21, 2025Updated 8mo ago
Risk Assessment

The "crm-customer-relationship-management-by-vcita" v2.8.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a clean code base with no detected dangerous functions, no raw SQL queries, and a relatively low attack surface with all identified entry points protected by authorization checks. The absence of taint analysis findings and critical/high severity vulnerabilities in its history is also a good indicator of proactive security measures in recent development.

However, several concerns warrant attention. The plugin has a history of 5 medium severity vulnerabilities, including Cross-site Scripting (XSS), Missing Authorization, and Cross-Site Request Forgery (CSRF). The fact that these were all medium severity issues and are currently unpatched in v2.8.1 suggests a recurring pattern of needing to address these types of flaws. Furthermore, while the majority of output is properly escaped (61% is a concern), the remaining 39% could potentially lead to XSS vulnerabilities if exploited, especially given the plugin's history of such issues.

In conclusion, while v2.8.1 has improved in some areas by securing its entry points and avoiding critical flaws in static analysis, the persistent history of medium severity vulnerabilities, particularly XSS and authorization issues, along with a significant portion of unescaped output, indicates that the plugin is not without risk. Users should be cautious and ensure they are using the latest available patched version of the plugin.

Key Concerns

  • History of 5 medium severity CVEs
  • Significant portion of output unescaped (39%)
  • History of XSS, Missing Auth, CSRF vulnerabilities
Vulnerabilities
5

CRM and Lead Management by vcita Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-5240medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM and Lead Management by vcita <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter

Jul 21, 2025 Patched in 2.8.0 (1d)
CVE-2024-13702medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM and Lead Management by vcita <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 25, 2025 Patched in 2.7.5 (1d)
CVE-2024-13703medium · 4.3Missing Authorization

CRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget Toggle

Mar 12, 2025 Patched in 2.8.0 (132d)
CVE-2023-2405medium · 6.1Cross-Site Request Forgery (CSRF)

CRM and Lead Management by vcita <= 2.7.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jun 2, 2023 Patched in 2.7.1 (658d)
CVE-2023-2404medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM and Lead Management by vcita <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 2, 2023 Patched in 2.7.0 (235d)
Code Analysis
Analyzed Mar 16, 2026

CRM and Lead Management by vcita Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
55 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

61% escaped90 total outputs
Attack Surface

CRM and Lead Management by vcita Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_vcita_ajax_toggle_aevcita-ajax-function.php:2
authwp_ajax_vcita_ajax_toggle_contactvcita-ajax-function.php:3
authwp_ajax_vcita_ajax_toggle_calendarvcita-ajax-function.php:4
WordPress Hooks 8
actionadmin_noticesvcita-client-management.php:18
actionplugins_loadedvcita-client-management.php:48
actionadmin_menuvcita-client-management.php:51
actionwp_headvcita-client-management.php:52
actionwp_enqueue_scriptsvcita-client-management.php:53
actionwp_enqueue_scriptsvcita-client-management.php:56
actionadmin_noticesvcita-settings-functions.php:35
filterplugin_action_linksvcita-utility-functions.php:15
Maintenance & Trust

CRM and Lead Management by vcita Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJul 23, 2025
PHP min version
Downloads43K

Community Trust

Rating72/100
Number of ratings5
Active installs100
Developer Profile

CRM and Lead Management by vcita Developer Profile

vcita

3 plugins · 1K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
171 days
View full developer profile
Detection Fingerprints

How We Detect CRM and Lead Management by vcita

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crm-customer-relationship-management-by-vcita/css/crm-customer-relationship-management-by-vcita.css/wp-content/plugins/crm-customer-relationship-management-by-vcita/js/crm-customer-relationship-management-by-vcita.js
Script Paths
/wp-content/plugins/crm-customer-relationship-management-by-vcita/js/crm-customer-relationship-management-by-vcita.js
Version Parameters
crm-customer-relationship-management-by-vcita/css/crm-customer-relationship-management-by-vcita.css?ver=crm-customer-relationship-management-by-vcita/js/crm-customer-relationship-management-by-vcita.js?ver=

HTML / DOM Fingerprints

CSS Classes
vcita-widget-wrapper
HTML Comments
<!-- vCita Widget Script -->
Data Attributes
data-vcita-widget-id
JS Globals
vcitaAjax
Shortcode Output
[vCitaMeetingScheduler][vCitaSchedulingCalendar]
FAQ

Frequently Asked Questions about CRM and Lead Management by vcita