CRITICAL 9.8 CVE-2026-84251 Published 11 Oct 2026

Click5 CRM Add-on for Ninja Forms WordPress Plugin Missing Authorization Vulnerability

Worried this affects your website?

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 has missing authorisation and CSRF checks when updating options via a REST endpoint.

The plugin also does not ensure that the option being updated belongs to the click5 CRM add-on.

  • Affected versions: through 1.0.1
  • Impact: unauthenticated attackers can change arbitrary blog options, create a new administrator account, and take over the site.

Reference: CVE-2026-84251 on NVD

← Back to Security News