CVE-2026-84259 PUBLISHED

click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications

Assigner: WPScan
Reserved: 01.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.

Product Status

Vendor Unknown
Product click5 CRM add-on to WPForms
Versions Default: unknown
  • affected from 0 to 1.0.3 (incl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE