External risk intelligence

Click5 CRM for Gravity Forms Arbitrary Blog Option Update Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84253

The vulnerability affects a WordPress plugin, which is inherently designed to be part of a web application. As a public-facing web platform, WordPress sites are commonly accessible via the internet, making the REST endpoints of such plugins reachable and exposed to the public internet by default in typical deployments.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress add-on that, if exploited, could allow unauthorized users to gain full control of a website by changing its settings. The primary concern is to confirm if this specific add-on is in use and potentially exposed.

  • Unauthenticated attackers can take over websites.
  • Critical flaw allows arbitrary website option changes.
  • Confirm usage to assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by interacting with a specific REST endpoint exposed by the click5 CRM add-on for Gravity Forms. Because this endpoint lacks proper authorization and checks, an attacker can trick the system into updating any blog option. This could ultimately allow an attacker to create a new administrator account and gain complete control over the WordPress site.

  • No authentication required to access.
  • Update arbitrary blog options via REST endpoint.
  • Full site takeover via admin account creation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to change arbitrary blog options on a WordPress site. When supported by the advisory, this could lead to the creation of a new administrator account and complete site takeover.

  • Arbitrary blog options.
  • Unauthenticated access to REST endpoint.
  • Complete website takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The click5 CRM add-on for Gravity Forms on WordPress is susceptible to remote code execution, allowing unauthenticated attackers to compromise the entire site by creating new administrator accounts. The primary responsibility for addressing this vulnerability likely falls to the application owner or the team managing the WordPress environment, in coordination with the security team. The first step is to identify all WordPress instances using this plugin, assess their exposure, and confirm ownership before planning remediation.

  • Application owners or WordPress administrators.
  • Verify plugin usage and external reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the click5 CRM add-on for Gravity Forms?

It is a WordPress plugin extension designed to integrate customer relationship management features directly into Gravity Forms. Users typically employ it to sync form submissions with their CRM platform, automating data collection and lead management within their existing WordPress dashboard.

How does CVE-2026-84253 affect site security?

This issue is a missing authorization vulnerability (CWE-862). It means the plugin fails to verify if a user has permission before allowing changes to system settings. Because of this flaw, the plugin can be tricked into modifying critical WordPress configuration values that dictate who has administrative access.

Do I need to be logged in to trigger this vulnerability?

No. The vulnerability exists in a REST endpoint that lacks access controls. An attacker does not need an existing account or administrative privileges to interact with it. Simply visiting the site and sending a specially crafted request to that endpoint is enough; internal WordPress user sessions are not required.

Why is this considered a significant risk for my website?

Halo Surface Signal notes that since WordPress is a public-facing platform, the REST endpoints used by plugins are generally reachable via the internet by default. This makes it highly likely that if the plugin is installed, the vulnerable endpoint is accessible to anyone online, increasing the likelihood of unauthorized configuration changes.

What is the first step to handle this threat?

Begin by auditing your WordPress site inventory to determine if the click5 CRM add-on is currently active. If you find the plugin, assess how your site is deployed and identify who is responsible for managing its configuration. Once usage is confirmed, focus on restricting access or disabling the plugin until you can apply official updates.

References