Sceawere
Vulnerability Detail
CVE-2026-84259UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in click5 CRM
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- click5 CRM add-on to WPForms
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:25.390Z",
"pubdate": "2026-10-11T07:17:25.390Z",
"executiveSummary": "The click5 CRM add-on for the WPForms WordPress plugin, versions up to and including 1.0.3, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from the improper handling of user-supplied data transmitted via an unauthenticated endpoint. Because the plugin fails to perform adequate input sanitization or output encoding before rendering this data within an administrative dashboard, it allows malicious actors to inject arbitrary JavaScript payloads.\nThe impact of this vulnerability is significant, as it enables the execution of malicious scripts within the browser context of authenticated administrative users. This effectively grants an attacker the capability to hijack active sessions, exfiltrate sensitive configuration data, perform unauthorized actions on behalf of the administrator, or manipulate the CRM environment. Given that the entry point is unauthenticated, this vulnerability poses a severe risk to the integrity and confidentiality of the WordPress installation. Organizations utilizing this plugin should prioritize immediate remediation to prevent potential exploitation by remote, unauthenticated adversaries.",
"technicalDetails": "The vulnerability resides in the data ingestion process of the click5 CRM add-on for WPForms. The plugin exposes an unauthenticated endpoint intended to receive submissions, which are subsequently stored in the application database. The core defect is the absence of rigorous server-side input sanitization or context-aware output escaping when these submitted values are retrieved and displayed in the WordPress administrative interface.\nThe attack flow begins when an unauthenticated attacker sends a crafted request containing a malicious payload—typically JavaScript code encased in HTML tags such as <script> or event handlers like onerror—to the vulnerable endpoint. The plugin accepts this input as valid data and commits it to the database without validation. When an administrator navigates to the specific CRM admin page where these submissions are rendered, the browser interprets the stored payload as executable script rather than plain text. This is a classic example of Stored XSS, where the persistence of the payload ensures execution every time the tainted content is viewed by an administrative user.\nBecause the payload executes within the context of an authenticated admin session, the attacker can bypass Same-Origin Policy (SOP) restrictions related to the WordPress site. The script can perform DOM manipulation, capture CSRF tokens to escalate privileges, modify user settings, or redirect the administrator to external malicious sites. Since the entry point requires no authentication, the attack vector is exposed to the public internet. The lack of output encoding ensures that the application implicitly trusts the data stored in the database, directly leading to the compromise of the victim's session integrity. The affected component is the internal data processing and display controller within the click5 CRM add-on, impacting all versions through 1.0.3."
}