CVE-2026-66642
5.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Summary
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery.
This issue affects WP Umbrella: from 2.24.2 through 2.26.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WP Umbrella | WP Umbrella | 2.24.2 <= 2.26.2 | affected |
Weaknesses
- CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://patchstack.com/database/wordpress/plugin/wp-health/vulnerability/wordpress-wp-umbrella-plugin-2-26-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve
- https://wp-umbrella.com/blog/security-disclosure-csrf-vulnerability-in-the-wp-umbrella-plugin-fixed-in-2-27-0/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.