Authorization Flaw in Click5 CRM Add-on for Contact Form 7 by WordPress
CVE-2026-84254
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-84254?
The Click5 CRM add-on for the Contact Form 7 WordPress plugin lacks adequate authorization and CSRF protections when updating settings via its REST endpoint. This vulnerability allows attackers without authentication to manipulate arbitrary options within the WordPress site. As a consequence, adversaries can escalate their privileges, potentially creating new administrator accounts and seizing full control over the website.
Affected Version(s)
click5 CRM add-on to Contact Form 7 0 <= 1.0.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.