External risk intelligence

Ninja Forms Click5 CRM Add-on WordPress Plugin Vulnerability Allows Full Site Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84251

The vulnerability affects a WordPress plugin, which is a component of a web application. WordPress sites are frequently deployed as internet-facing web services. Since the vulnerability is reachable via a REST endpoint without authorization, it is commonly accessible to external internet traffic.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress plugin, specifically the click5 CRM add-on, allowing unauthenticated attackers to change website settings. At a high level, this could enable them to take over the entire site by creating new administrator accounts.

  • Unauthenticated attackers can alter website settings.
  • Site takeover is possible by creating admin accounts.
  • Confirm relevance and exposure across your digital assets.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by sending unauthenticated requests to a specific REST endpoint in the click5 CRM add-on for Ninja Forms. This endpoint allows for the updating of plugin options without proper authorization or checks, enabling attackers to modify any blog option. If successful, an attacker can create a new administrator account, leading to complete website takeover.

  • Unauthenticated access to a REST endpoint.
  • Arbitrary blog option updates.
  • Full website takeover via new admin.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could change arbitrary blog options through a vulnerable REST endpoint. This could allow them to create a new administrator account and gain full control of the website.

  • Blog options and website administration.
  • Updating options via an unprotected REST endpoint.
  • Full website takeover and new administrator account.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, website owners and administrators should prioritize identifying all instances of the affected WordPress plugin. Confirming its reachability and business criticality is essential to assess risk and determine the appropriate remediation timeline, potentially involving coordination with the plugin vendor.

  • Website owners and administrators
  • Verify plugin reachability and impact
  • Plan vendor-coordinated remediation

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the click5 CRM add-on for Ninja Forms?

It is a WordPress plugin extension designed to integrate customer relationship management features with the popular Ninja Forms contact form builder. Users rely on this add-on to automatically sync form entries and user data directly into their CRM systems, streamlining lead generation and customer tracking workflows within their WordPress dashboard.

How does CVE-2026-84251 lead to site takeover?

This vulnerability is a Missing Authorization issue, categorized as CWE-862. Because the plugin lacks proper security checks on a specific REST endpoint, an attacker can bypass access controls to modify internal WordPress configuration settings. By changing these options, they can create a new administrator account, granting them full control over the website's administrative functions.

Do I need to be logged in to trigger this vulnerability?

No. The flaw exists because the affected REST endpoint does not require any authentication or user permissions to process requests. An attacker can reach this endpoint remotely without having an existing account on the site. Simply interacting with the specific, unprotected plugin path is enough to initiate the unauthorized change of blog settings.

Why is this CVE considered high risk for my site?

Halo Surface Signal flags this as a significant concern because the vulnerability resides in an internet-facing WordPress plugin. Since the flaw is accessible via a public web request and requires no prior login, the barrier for an attacker is extremely low. If your site is connected to the internet, this plugin component acts as a direct, unprotected gateway.

Is there a first step to take if I run this software?

Begin by auditing your WordPress site to confirm if the click5 CRM add-on is installed and active. Once identified, evaluate whether the plugin is essential for your current business operations. If it is not strictly necessary, deactivate and remove it immediately to eliminate the attack surface while you monitor for official patches or updates from the vendor.

References