Sceawere
Vulnerability Detail
CVE-2026-84252UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Options Update Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- click5 CRM add-on to WPForms
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to WPForms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-11T07:17:24.943Z",
"pubdate": "2026-10-11T07:17:24.943Z",
"executiveSummary": "The click5 CRM add-on to WPForms WordPress plugin, versions 1.0.3 and below, contains a critical security flaw involving improper access control and Cross-Site Request Forgery (CSRF) protection on a REST API endpoint. This vulnerability allows an unauthenticated, remote attacker to manipulate arbitrary WordPress site options.\nThe primary risk stems from the ability to modify core settings such as the 'users_can_register' and 'default_role' parameters, which can be leveraged to escalate privileges and facilitate a full site takeover. By reconfiguring these options, an attacker can create a new administrative account, effectively gaining total control over the compromised WordPress installation.\nThis vulnerability is particularly severe because it requires no prior authentication, lowering the barrier to entry for malicious actors. The absence of strict input validation allows the plugin to update any setting in the wp_options table, including those outside the scope of the plugin itself. Organizations utilizing this add-on are exposed to unauthorized administrative access and potential data exfiltration or site defacement. Remediation requires an immediate audit of exposed REST endpoints and the implementation of robust authorization checks.",
"technicalDetails": "The vulnerability resides within the REST API implementation of the click5 CRM add-on to WPForms. The plugin registers a REST endpoint designed to update internal settings; however, the associated handler function fails to perform mandatory capability checks. Specifically, the function does not verify if the requestor possesses the 'manage_options' capability, nor does it implement nonces to prevent CSRF attacks.\nThe root cause is a failure in the endpoint's access control logic, which relies on the client's request without validating identity or intent. Furthermore, the handler fails to sanitize or constrain the scope of the keys being updated. By design, WordPress REST API handlers should validate that the provided key belongs to the plugin's registered namespace. In this instance, the plugin allows the modification of any entry within the 'wp_options' table.\nThe exploitation flow proceeds as follows: An unauthenticated attacker crafts a malicious HTTP POST request targeting the exposed REST API endpoint. Because the plugin lacks authorization checks, the server processes the request as if it were an authorized administrator action. The payload specifies the key-value pair to be modified. For example, an attacker can target the 'users_can_register' option and set its value to '1', subsequently setting 'default_role' to 'administrator'.\nOnce these options are modified, the attacker can navigate to the standard WordPress registration page (e.g., /wp-login.php?action=register) and create a new user account. Due to the manipulated settings, this new account is automatically granted full administrative privileges. This provides the attacker with a persistent backdoor via the WordPress dashboard, enabling them to execute arbitrary code, modify themes, install malicious plugins, or exfiltrate sensitive site data.\nThe lack of proper input validation regarding which options are modified means the scope of impact extends to any configurable WordPress option, making this an extremely high-risk vulnerability. The flaw exists specifically within the plugin's REST API handling logic, which is reachable globally without any requirement for valid session tokens or cryptographic nonces. This vulnerability underscores the critical importance of strictly enforcing 'permission_callback' in the WordPress REST API to ensure only authorized users can perform sensitive configuration updates."
}