CVE-2026-66642
WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF) vulnerability
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.
| CWE | CWE-352 |
| Vendor | wp umbrella |
| Product | wp umbrella |
| Published | Aug 10, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for wp umbrella wp umbrella
Be the first to know when new medium vulnerabilities affecting wp umbrella wp umbrella are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
WP Umbrella / WP Umbrella
2.24.2 โค 2.26.2
References
patchstack.com: https://patchstack.com/database/wordpress/plugin/wp-health/vulnerability/wordpress-wp-umbrella-plugin-2-26-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve wp-umbrella.com: https://wp-umbrella.com/blog/security-disclosure-csrf-vulnerability-in-the-wp-umbrella-plugin-fixed-in-2-27-0/
Credits
Anthony Green [Antnation] | Patchstack Bug Bounty Program