CRITICAL 9.8 CVE-2026-84254 Published 11 Oct 2026

WordPress Contact Form 7 click5 CRM Add-On Missing Authorization Vulnerability

Worried this affects your website?

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 contains a missing authorization and CSRF check vulnerability in its REST endpoint for updating options.

The plugin does not ensure that the option being updated belongs to the click5 CRM add-on, and the endpoint lacks authorization and CSRF protections.

  • Affected versions: through 1.0.4
  • Attackers: unauthenticated
  • Impact: arbitrary blog options can be changed, allowing creation of a new administrator account and full site takeover.

Reference: CVE-2026-84254 on NVD

← Back to Security News