Sceawere
Vulnerability Detail
CVE-2026-84251UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Options Update Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- click5 CRM add-on to Ninja Forms
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-11T07:17:24.820Z",
"pubdate": "2026-10-11T07:17:24.820Z",
"executiveSummary": "The click5 CRM add-on for Ninja Forms (up to version 1.0.1) contains a critical security vulnerability involving the lack of authorization and Cross-Site Request Forgery (CSRF) protection within its REST API endpoints.\nThis flaw allows unauthenticated, remote attackers to manipulate arbitrary site options within the WordPress database.\nBy modifying sensitive settings—such as 'users_can_register' and the 'default_role'—an attacker can gain unauthorized administrative privileges.\nThe impact of this vulnerability is severe, effectively allowing for complete site takeover via account creation or configuration manipulation.\nThe vulnerability stems from improper input validation and access control implementation on the REST API, enabling unauthorized write access to the options table without requiring elevated privileges or session validation.",
"technicalDetails": "The vulnerability resides within the REST API implementation of the click5 CRM add-on for Ninja Forms, specifically affecting versions 1.0.1 and prior.\nThe root cause of this flaw is the absence of capability checks and CSRF validation within the endpoint responsible for updating plugin options. The code fails to implement proper sanitization or validation to ensure that the request originates from an authorized administrator.\nFurthermore, the function logic does not restrict the scope of the options update process. It fails to verify if the requested option key is intended for use by the click5 CRM add-on, allowing the endpoint to interact with any entry within the WordPress 'wp_options' table.\nAn attacker can exploit this by sending a crafted HTTP request to the vulnerable REST endpoint. Since the plugin does not enforce authentication or verify security tokens (nonces), the request is processed by the server as a legitimate administrative action.\nThe attack flow begins with the attacker identifying the target endpoint. Because no authentication is required, the attacker can leverage standard HTTP methods (such as POST or PUT) to modify critical WordPress configuration settings.\nA common exploitation vector involves changing the 'users_can_register' setting to '1' and setting the 'default_role' to 'administrator'. Once these options are modified, the attacker can navigate to the standard WordPress registration page, create a new account, and immediately assume administrative control of the application.\nPost-exploitation, the attacker has full administrative access to the WordPress environment. This enables the execution of arbitrary code via plugin or theme uploads, exfiltration of sensitive database contents, and complete system compromise.\nThe vulnerability is exposed over the network, making any site with this plugin installed and the REST API enabled susceptible to unauthenticated remote exploitation without any prior user interaction or privilege requirements."
}