CRITICAL
9.8 CVE-2026-84254 Published 11 Oct 2026
WordPress Contact Form 7 click5 CRM Add-On Missing Authorization Vulnerability
Worried this affects your website?
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 contains a missing authorization and CSRF check vulnerability in its REST endpoint for updating options.
The plugin does not ensure that the option being updated belongs to the click5 CRM add-on, and the endpoint lacks authorization and CSRF protections.
- Affected versions: through 1.0.4
- Attackers: unauthenticated
- Impact: arbitrary blog options can be changed, allowing creation of a new administrator account and full site takeover.
Reference: CVE-2026-84254 on NVD
← Back to Security News