CRITICAL 9.8 CVE-2026-84253 Published 11 Oct 2026

WordPress Click5 CRM Add-On Arbitrary Option Update Vulnerability

Worried this affects your website?

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 lacks authorisation and CSRF checks when updating options via a REST endpoint.

It also does not ensure that the option to be updated belongs to the plugin.

  • Affected versions: through 1.0.3
  • Impact: unauthenticated attackers can change arbitrary blog options, create a new administrator account, and take over the site.

Reference: CVE-2026-84253 on NVD

← Back to Security News