Sceawere

Vulnerability Detail

CVE-2026-84260UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in click5 CRM

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
click5 CRM add-on to Gravity Forms
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T07:17:25.483Z",
  "pubdate": "2026-10-11T07:17:25.483Z",
  "executiveSummary": "The click5 CRM add-on for the Gravity Forms WordPress plugin (up to version 1.0.3) contains a critical Stored Cross-Site Scripting (XSS) vulnerability. This flaw stems from improper input validation and output encoding within an unauthenticated endpoint, allowing attackers to inject arbitrary malicious scripts into the application.\nBecause the payload is stored within the system and subsequently rendered in administrative interface pages, an attacker can execute unauthorized code within the session context of a high-privileged user, such as a WordPress administrator. This bypasses typical authentication constraints, as the attack is triggered by the victim simply accessing the compromised admin dashboard.\nSuccessful exploitation poses significant risk, potentially leading to unauthorized data exfiltration, administrative account takeover, configuration changes, or the injection of additional malicious content. The vulnerability is particularly severe due to the unauthenticated nature of the input vector, which requires no prior system access to trigger, making it an ideal target for automated exploitation. Organizations utilizing affected versions are strongly advised to restrict access or apply updates immediately upon availability.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), originating from the failure of the click5 CRM add-on to sanitize or escape user-supplied data accepted via an unauthenticated endpoint. In WordPress plugin architecture, such endpoints often interface directly with database entry points for form submissions or lead generation, failing to verify data integrity before persistent storage.\nThe root cause is the lack of output escaping when the administrative interface retrieves and displays the stored content. When the CRM add-on renders entries captured from the unauthenticated endpoint within the plugin's administrative dashboard, the browser interprets any included HTML or JavaScript tags as legitimate markup rather than plain text. This allows for the injection of malicious payloads that execute within the security context of the authenticated administrator.\nThe attack flow begins with an unauthenticated remote attacker sending a crafted HTTP request to the specific endpoint handled by the click5 CRM add-on. This request contains a malicious JavaScript payload embedded within fields that are expected to be treated as user-input data (e.g., form submissions or CRM contact details). The plugin accepts this input without validation and stores it directly into the WordPress database.\nThe exploitation phase occurs when a high-privileged user, typically an administrator, navigates to the plugin's dashboard to review the collected data. Upon page load, the plugin retrieves the malicious payload from the database and inserts it into the Document Object Model (DOM) of the admin page without appropriate context-aware output encoding. The browser, trusting the source, executes the injected JavaScript.\nThe impact is significant: the injected script can access the administrator's session cookies, perform unauthorized administrative actions via forged requests (Cross-Site Request Forgery/XSRF), capture sensitive CRM data, or redirect the administrator to external malicious sites. Since the code runs with the privileges of the active admin session, it can theoretically leverage the WordPress REST API or admin-ajax.php to execute further malicious operations, such as creating new rogue accounts or modifying system configuration files. Because this is a Stored XSS variant, the payload remains persistent, ensuring that the malicious code executes every time an administrator views the compromised entries, maximizing the likelihood of successful compromise."
}
CVE-2026-84260: Stored XSS in click5 CRM (HIGH Severity, CVSS: 8.8) | Sceawere