CRITICAL 9.8 CVE-2026-84252 Published 11 Oct 2026

WPForms Click5 CRM Add-On Arbitrary Option Update Vulnerability

Worried this affects your website?

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 contains a missing authorization and CSRF check vulnerability in a REST endpoint used to update options.

Because the endpoint lacks authorization and CSRF checks, and does not verify that the option belongs to the plugin, unauthenticated attackers can change arbitrary blog options.

  • Affected versions: through 1.0.3
  • Impact: attackers can create a new administrator account and take over the site.

Reference: CVE-2026-84252 on NVD

← Back to Security News