Stored XSS Vulnerability in Click5 CRM Add-On for WPForms
CVE-2026-84259
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2026
Badges
What is CVE-2026-84259?
The Click5 CRM add-on to the WPForms WordPress plugin versions up to 1.0.3 contains a security flaw that fails to properly sanitize and escape input submitted through an unauthenticated endpoint. This oversight can lead to Stored Cross-Site Scripting (XSS) vulnerabilities, potentially exposing high privilege users, such as administrators, to malicious scripts that can be executed in their browsers when they access the admin page. This vulnerability highlights the importance of thorough input validation and sanitization in web applications to maintain secure user environments.
Affected Version(s)
click5 CRM add-on to WPForms 0 <= 1.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.