CRITICAL
9.8 CVE-2026-84251 Published 11 Oct 2026
Click5 CRM Add-on for Ninja Forms WordPress Plugin Missing Authorization Vulnerability
Worried this affects your website?
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 has missing authorisation and CSRF checks when updating options via a REST endpoint.
The plugin also does not ensure that the option being updated belongs to the click5 CRM add-on.
- Affected versions: through 1.0.1
- Impact: unauthenticated attackers can change arbitrary blog options, create a new administrator account, and take over the site.
Reference: CVE-2026-84251 on NVD
← Back to Security News