Sceawere
Vulnerability Detail
CVE-2026-84258UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in click5 CRM
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- click5 CRM add-on to Ninja Forms
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:25.287Z",
"pubdate": "2026-10-11T07:17:25.287Z",
"executiveSummary": "The click5 CRM add-on for the Ninja Forms WordPress plugin, in versions up to 1.0.1, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from the application's failure to properly sanitize and escape user-supplied data transmitted through an unauthenticated endpoint.\nBy submitting malicious payloads via this endpoint, an unauthenticated remote attacker can inject arbitrary JavaScript into the WordPress administrative dashboard. When an administrator views the affected admin page, the malicious script executes within their session context.\nThe impact of this vulnerability is severe, as successful exploitation allows an attacker to perform actions on behalf of the administrator, potentially leading to unauthorized plugin modifications, site configuration changes, or the exfiltration of sensitive administrative data. Because the exploit targets high-privilege users, this flaw poses a significant risk to the integrity and security of the entire WordPress installation. No special user privileges are required for an attacker to initiate the injection, making this an highly accessible vector for compromise.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the inadequate processing of user-supplied input within the click5 CRM add-on for Ninja Forms. The root cause lies in the application's implementation of an unauthenticated API endpoint that accepts input without performing server-side validation, sanitization, or context-aware output encoding.\nThe attack flow begins when an attacker sends a crafted HTTP request to the vulnerable unauthenticated endpoint. This request contains a malicious JavaScript payload embedded within the input fields that the plugin expects to process. Because the plugin logic persists this data directly into the WordPress database without sanitization, the malicious payload is stored permanently within the system.\nThe vulnerability is triggered when an administrative user accesses a specific admin page within the WordPress dashboard where the plugin retrieves and outputs the stored data. Since the application fails to utilize proper output escaping mechanisms (such as esc_html() or esc_js() provided by the WordPress API), the browser interprets the injected JavaScript as legitimate content and executes it within the context of the administrator's authenticated session.\nThis execution allows the attacker's script to perform a wide range of unauthorized actions. Given that the script runs with the administrative user's privileges, the attacker can leverage the browser's DOM to perform actions such as making API calls to the WordPress REST API to create new administrative accounts, modifying plugin settings, or exfiltrating sensitive session tokens, cookies, and internal data. The exposure is total, as the malicious code can interact with any resource accessible to the administrator's browser session. The vulnerability affects all versions of the click5 CRM add-on up to and including 1.0.1, and its exploitation requires no authentication, allowing any remote user to store the payload on the target site."
}