Description
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Accessibility Helper (WAH) plugin up to version 0.6.6 contains an unauthenticated CSRF flaw identified as CWE‑352. A crafted request can be sent to the WordPress site and, because the request does not require authentication, any logged‑in user who visits the malicious page will have their plugin settings or actions altered. The potential impact includes unauthorized modification of accessibility settings or execution of any plugin‑authorized operation, thereby affecting configuration integrity and user experience.

Affected Systems

The vulnerability affects the WordPress WP Accessibility Helper (WAH) plugin developed by Alex Volkov. All releases up to and including 0.6.6 are impacted. Any WordPress installation that has the plugin installed in a vulnerable version is at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate complexity and lower overall impact. The EPSS score of less than 1% reflects a very low probability of real‑world exploitation at the time of this analysis. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by delivering a forged HTTP request from a malicious webpage that a target authenticated user will load, leveraging the acquired user privileges to perform plugin actions.

Generated by OpenCVE AI on August 3, 2026 at 22:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Accessibility Helper to version 0.6.7 or later where the flaw is resolved
  • If a newer version is unavailable, uninstall the plugin entirely
  • Disable the plugin for non‑administrator roles or restrict its functions via role‑based access controls
  • Implement CSRF tokens in any custom plugin code that interacts with WP Accessibility Helper

Generated by OpenCVE AI on August 3, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Alex Volkov
Alex Volkov wp Accessibility Helper
Wordpress
Wordpress wordpress
Vendors & Products Alex Volkov
Alex Volkov wp Accessibility Helper
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
Title WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Alex Volkov Wp Accessibility Helper
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:35:15.992Z

Reserved: 2026-01-23T12:31:40.820Z

Link: CVE-2026-24537

cve-icon Vulnrichment

Updated: 2026-07-23T13:35:10.222Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:12.527

Modified: 2026-07-23T14:17:09.527

Link: CVE-2026-24537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)