Sceawere

Vulnerability Detail

CVE-2026-84251UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Options Update Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
click5 CRM add-on to Ninja Forms
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:24.820Z",
  "pubdate": "2026-10-11T07:17:24.820Z",
  "executiveSummary": "The click5 CRM add-on for Ninja Forms (up to version 1.0.1) contains a critical security vulnerability involving the lack of authorization and Cross-Site Request Forgery (CSRF) protection within its REST API endpoints.\nThis flaw allows unauthenticated, remote attackers to manipulate arbitrary site options within the WordPress database.\nBy modifying sensitive settings—such as 'users_can_register' and the 'default_role'—an attacker can gain unauthorized administrative privileges.\nThe impact of this vulnerability is severe, effectively allowing for complete site takeover via account creation or configuration manipulation.\nThe vulnerability stems from improper input validation and access control implementation on the REST API, enabling unauthorized write access to the options table without requiring elevated privileges or session validation.",
  "technicalDetails": "The vulnerability resides within the REST API implementation of the click5 CRM add-on for Ninja Forms, specifically affecting versions 1.0.1 and prior.\nThe root cause of this flaw is the absence of capability checks and CSRF validation within the endpoint responsible for updating plugin options. The code fails to implement proper sanitization or validation to ensure that the request originates from an authorized administrator.\nFurthermore, the function logic does not restrict the scope of the options update process. It fails to verify if the requested option key is intended for use by the click5 CRM add-on, allowing the endpoint to interact with any entry within the WordPress 'wp_options' table.\nAn attacker can exploit this by sending a crafted HTTP request to the vulnerable REST endpoint. Since the plugin does not enforce authentication or verify security tokens (nonces), the request is processed by the server as a legitimate administrative action.\nThe attack flow begins with the attacker identifying the target endpoint. Because no authentication is required, the attacker can leverage standard HTTP methods (such as POST or PUT) to modify critical WordPress configuration settings.\nA common exploitation vector involves changing the 'users_can_register' setting to '1' and setting the 'default_role' to 'administrator'. Once these options are modified, the attacker can navigate to the standard WordPress registration page, create a new account, and immediately assume administrative control of the application.\nPost-exploitation, the attacker has full administrative access to the WordPress environment. This enables the execution of arbitrary code via plugin or theme uploads, exfiltration of sensitive database contents, and complete system compromise.\nThe vulnerability is exposed over the network, making any site with this plugin installed and the REST API enabled susceptible to unauthenticated remote exploitation without any prior user interaction or privilege requirements."
}
CVE-2026-84251: Unauthenticated Options Update Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere