OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-84260 (CVSS 8.8)

NVD · officialPublished Oct 11, 2026Risk 37/100EPSS 0.2%

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source