CRITICAL
9.8 CVE-2026-84253 Published 11 Oct 2026
WordPress Click5 CRM Add-On Arbitrary Option Update Vulnerability
Worried this affects your website?
The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 lacks authorisation and CSRF checks when updating options via a REST endpoint.
It also does not ensure that the option to be updated belongs to the plugin.
- Affected versions: through 1.0.3
- Impact: unauthenticated attackers can change arbitrary blog options, create a new administrator account, and take over the site.
Reference: CVE-2026-84253 on NVD
← Back to Security News