Sceawere

Vulnerability Detail

CVE-2026-84253UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Arbitrary Option Update

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
click5 CRM add-on to Gravity Forms
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:25.057Z",
  "pubdate": "2026-10-11T07:17:25.057Z",
  "executiveSummary": "The click5 CRM add-on to Gravity Forms WordPress plugin (versions 1.0.3 and below) contains a critical security flaw involving improper access control within its REST API implementation.\nThe vulnerability is characterized as an Unauthenticated Arbitrary Option Update, allowing remote, unauthenticated attackers to modify arbitrary settings within the WordPress 'wp_options' database table.\nBy bypassing authorization and Cross-Site Request Forgery (CSRF) protections, an attacker can manipulate sensitive configuration options, such as enabling user registration or modifying site administrator roles.\nThis vulnerability poses a critical risk to site integrity and confidentiality, as it facilitates full site takeover through the creation of rogue administrative accounts.\nSuccessful exploitation requires no prior authentication, significantly lowering the barrier to entry for malicious actors targeting installations of this specific plugin.",
  "technicalDetails": "The vulnerability resides within the REST API endpoint exposed by the click5 CRM add-on to Gravity Forms. The plugin fails to perform adequate authorization checks or validate the origin of requests, effectively disabling security barriers that should restrict access to sensitive administrative functions.\nThe root cause is the absence of permission checks (such as 'current_user_can()') within the REST endpoint responsible for updating plugin options. Furthermore, the endpoint lacks logic to restrict the scope of modifiable database keys, failing to ensure that only settings belonging to the click5 CRM add-on are mutable. Because the underlying logic uses standard WordPress update functions without context-aware validation, the API allows any global option present in the 'wp_options' table to be overwritten.\nThe exploitation flow begins when an unauthenticated attacker sends a crafted POST request to the vulnerable REST endpoint. Since the plugin does not verify the requester's identity or check for a valid non-deterministic token, the request is processed by the server with the privileges of the application's process.\nAn attacker can leverage this primitive to modify critical WordPress configuration values. A common vector involves setting 'users_can_register' to '1' and modifying the 'default_role' to 'administrator'. Once these options are manipulated, the attacker can register a new account through the standard WordPress registration page, which will automatically be granted administrative privileges.\nAlternatively, an attacker could change the 'siteurl' or 'home' options to redirect traffic to a malicious domain, or disable security-related plugins by toggling their 'active_plugins' configuration. This level of control provides the attacker with a stable backdoor, enabling persistent access even if the initial exploit vector is remediated. The lack of CSRF protection further ensures that attackers can trigger these changes via malicious scripts or social engineering if direct API access is restricted by network-level firewalls."
}
CVE-2026-84253: Unauthenticated Arbitrary Option Update (CRITICAL Severity, CVSS: 9.8) | Sceawere