CVE-2026-84261: click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Stored XSS via post_notifications
Published Oct 11, 2026
·Updated
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
Affected Software
1 affected component
click5 CRM add-on to Contact Form 7<=1.0.4
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness