External risk intelligence

WPForms click5 CRM add-on Unauthenticated Option Updates Allow Site Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84252

The vulnerability affects a WordPress plugin, which is a type of software commonly deployed as a public-facing web application. Since the vulnerability is reachable via a REST endpoint accessible to external users, it is likely to be exposed to the public internet in common deployments.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue involves a WordPress plugin that, without proper security checks, allows unauthorized individuals to alter site settings, potentially leading to a complete website takeover. The primary concern is confirming if this specific plugin is in use and if it is exposed externally.

  • Unauthenticated users can gain full site control.
  • Protects against unauthorized site administration.
  • Verify plugin usage and external exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by interacting with a REST endpoint. This endpoint, lacking proper authorization and cross-site request forgery checks, allows attackers to modify arbitrary blog options. Successful exploitation enables an attacker to create a new administrator account, leading to complete site takeover.

  • No authentication required.
  • Modifying arbitrary blog options.
  • Full website takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to alter critical WordPress site settings when the click5 CRM add-on is used. Such changes could include the creation of a new administrator account, leading to complete site compromise.

  • Arbitrary blog options could be changed.
  • Unauthenticated requests to a REST endpoint.
  • Complete website takeover is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WordPress plugin, which allows for unauthorized changes to blog options and potential site takeover, likely impacts website owners and the teams managing their WordPress instances. The first step is to identify all WordPress sites using the affected plugin, confirm their exposure and business criticality, and then determine the accountable owner for remediation.

  • Website owners and platform teams.
  • Confirm plugin usage and site exposure.
  • Plan remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the click5 CRM add-on for WordPress?

The click5 CRM add-on is a specific extension designed to integrate WordPress-based forms with CRM functionality. It bridges user-submitted data from WPForms into external customer relationship management systems. Because it operates as a plugin, it functions within the WordPress environment to handle data processing and configuration tasks, making it a critical component for businesses that manage customer information directly through their website forms.

What does CVE-2026-84252 mean for security?

This CVE describes a weakness identified as CWE-862, which is a lack of proper authorization. In simple terms, the software fails to verify that a user is allowed to perform specific actions before executing them. Because this check is missing, the plugin allows unauthorized people to interact with its REST endpoint and change internal blog settings, which can be manipulated to grant the attacker full administrative control over the entire WordPress site.

How does an attacker trigger this vulnerability?

An attacker triggers this bug by sending a specially crafted request to the plugin's REST endpoint. No prior login or special permissions are needed. It is important to note that the vulnerability does not require the attacker to be a registered user or have existing access to the site dashboard. Simply interacting with the vulnerable endpoint is sufficient to modify site options, as the system fails to validate whether the requested changes are authorized.

Do I need to worry if my site is not public-facing?

According to Halo Surface Signal, this vulnerability is classified as external because it targets a REST endpoint typically reachable over the internet. If your WordPress site is strictly internal or isolated from public access, the immediate threat is significantly reduced. However, you should still evaluate if any services or users could reach the endpoint. If your site is accessible from the public internet, it should be treated as a high-priority risk.

What is the first step to handle this vulnerability?

Your first step is to confirm whether the click5 CRM add-on for WPForms is currently active on any of your WordPress installations. Once you have an accurate inventory of affected sites, prioritize them based on their business importance and public accessibility. While you plan for updates or removal of the plugin, ensure you have robust backups of your site configurations and monitor for any suspicious administrative account activity.

References