Sceawere

Vulnerability Detail

CVE-2026-84254UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Option Update Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
click5 CRM add-on to Contact Form 7
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:25.180Z",
  "pubdate": "2026-10-11T07:17:25.180Z",
  "executiveSummary": "The click5 CRM add-on to Contact Form 7 WordPress plugin through version 1.0.4 contains a critical security flaw involving improper authorization and lack of Cross-Site Request Forgery (CSRF) protections within its REST API endpoint.\nThe vulnerability allows an unauthenticated, remote attacker to manipulate arbitrary WordPress site options via the plugin's REST endpoint. By failing to validate that the requested option update pertains strictly to the plugin's configuration, the vulnerability exposes the global wp_options table to unauthorized modification.\nThe primary risk implication is complete site compromise. By modifying critical WordPress options, such as 'users_can_register' or 'default_role', an attacker can facilitate unauthorized privilege escalation, such as creating a new administrative account or modifying authentication settings.\nNo authentication or specific privileges are required for exploitation, making this a high-severity remote code execution-adjacent vulnerability. The attack vector is entirely network-based, utilizing the exposed REST endpoint to execute unauthorized write operations.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure implementation of a REST API endpoint within the click5 CRM add-on to Contact Form 7. The plugin fails to implement necessary permission checks (such as 'current_user_can') or nonce validation to verify the legitimacy of requests targeting the update of WordPress configuration options.\nThe vulnerable component is the REST API handler responsible for processing option updates. When a request is sent to the endpoint, the application logic proceeds to update the database without restricting the scope of the keys being modified. Specifically, the code lacks an allow-list or context-aware validation mechanism that would prevent the modification of sensitive 'wp_options' rows.\nThe attack flow proceeds as follows: An attacker identifies the exposed REST endpoint associated with the click5 CRM add-on. Because the plugin does not mandate authentication, the attacker can craft a malicious HTTP request (typically a POST or PUT request) containing arbitrary keys and values intended for the database. By targeting existing WordPress options, the attacker can reconfigure the site's behavior.\nA common exploitation path involves setting the 'users_can_register' option to '1' and modifying 'default_role' to 'administrator'. Once these options are updated, the attacker can navigate to the WordPress registration page, create an account with administrative privileges, and gain full control over the site.\nThis vulnerability persists in all versions of the plugin through 1.0.4. Because the endpoint is publicly accessible, no prior interaction with the administrative interface is required. The lack of CSRF tokens means that the endpoint is also susceptible to automated exploitation via cross-site requests, where an attacker could trick an authenticated administrator into making the request; however, given the lack of authentication requirements, direct exploitation is trivial.\nThe post-exploitation impact is catastrophic, as the attacker effectively bypasses the entire WordPress access control model. By compromising the administration panel, the attacker can execute arbitrary PHP code through theme or plugin file editing, install backdoors, steal sensitive customer data from the CRM, or redirect traffic to malicious external domains, leading to a total loss of confidentiality, integrity, and availability for the affected installation."
}
CVE-2026-84254: Unauthenticated Option Update Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere