CRITICAL
9.8 CVE-2026-84252 Published 11 Oct 2026
WPForms Click5 CRM Add-On Arbitrary Option Update Vulnerability
Worried this affects your website?
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 contains a missing authorization and CSRF check vulnerability in a REST endpoint used to update options.
Because the endpoint lacks authorization and CSRF checks, and does not verify that the option belongs to the plugin, unauthenticated attackers can change arbitrary blog options.
- Affected versions: through 1.0.3
- Impact: attackers can create a new administrator account and take over the site.
Reference: CVE-2026-84252 on NVD
← Back to Security News