WordPress Plugin Vulnerabilities

click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Arbitrary Options Update

Description

The plugin does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-10 (about 8 hours ago)

Other