🔐 CVE Alert

CVE-2026-24537

MEDIUM 4.3

WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

CWE CWE-352
Vendor alex volkov
Product wp accessibility helper (wah)
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for alex volkov wp accessibility helper (wah)

Be the first to know when new medium vulnerabilities affecting alex volkov wp accessibility helper (wah) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Alex Volkov / WP Accessibility Helper (WAH)
n/a ≤ 0.6.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/wordpress/plugin/wp-accessibility-helper/vulnerability/wordpress-wp-accessibility-helper-wah-plugin-0-6-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve

Credits

Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program