PatchSiren

click5 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review click5 CVE published 2026-10-11

CVE-2026-84260

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. This vulnerability allows attackers to inject malicious scripts into pages viewed by administrators, potentially leading to u [truncated]

Review click5 CVE published 2026-10-11

CVE-2026-84259

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 has a Stored XSS vulnerability due to insufficient sanitization and escaping of content submitted through an unauthenticated endpoint. This could be used against high privilege users such as admin. Defenders should assess exposure and prioritize verification of the plugin version and monitoring for suspicious activity on the admin page. The v [truncated]

Review Click5 CVE published 2026-10-11

CVE-2026-84258

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. This vulnerability allows attackers to inject malicious scripts into pages viewed by administrators, potentially leading to una [truncated]

Review click5 CVE published 2026-10-11

CVE-2026-84254

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 has a security vulnerability. It lacks authorization and CSRF checks when updating options via a REST endpoint and does not verify that the option to be updated belongs to the plugin. This allows unauthenticated attackers to change arbitrary blog options, potentially creating a new administrator account and taking over the site.

Review click5 CVE published 2026-10-11

CVE-2026-84252

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 has a security vulnerability. It lacks authorization and CSRF checks when updating options via a REST endpoint and does not verify that the option to be updated belongs to the plugin. This allows unauthenticated attackers to change arbitrary blog options, potentially creating a new administrator account and taking over the site.