Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects a WordPress add-on that, if exploited, could allow unauthorized users to gain full control of a website by changing its settings. The primary concern is to confirm if this specific add-on is in use and potentially exposed.
- Unauthenticated attackers can take over websites.
- Critical flaw allows arbitrary website option changes.
- Confirm usage to assess potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by interacting with a specific REST endpoint exposed by the click5 CRM add-on for Gravity Forms. Because this endpoint lacks proper authorization and checks, an attacker can trick the system into updating any blog option. This could ultimately allow an attacker to create a new administrator account and gain complete control over the WordPress site.
- No authentication required to access.
- Update arbitrary blog options via REST endpoint.
- Full site takeover via admin account creation.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to change arbitrary blog options on a WordPress site. When supported by the advisory, this could lead to the creation of a new administrator account and complete site takeover.
- Arbitrary blog options.
- Unauthenticated access to REST endpoint.
- Complete website takeover.
Operational Fix
Recommended remediation, mitigation, and detection steps
The click5 CRM add-on for Gravity Forms on WordPress is susceptible to remote code execution, allowing unauthenticated attackers to compromise the entire site by creating new administrator accounts. The primary responsibility for addressing this vulnerability likely falls to the application owner or the team managing the WordPress environment, in coordination with the security team. The first step is to identify all WordPress instances using this plugin, assess their exposure, and confirm ownership before planning remediation.
- Application owners or WordPress administrators.
- Verify plugin usage and external reachability.
- Plan remediation based on identified risk.