Impact
The WP Accessibility Helper (WAH) plugin up to version 0.6.6 contains an unauthenticated CSRF flaw identified as CWE‑352. A crafted request can be sent to the WordPress site and, because the request does not require authentication, any logged‑in user who visits the malicious page will have their plugin settings or actions altered. The potential impact includes unauthorized modification of accessibility settings or execution of any plugin‑authorized operation, thereby affecting configuration integrity and user experience.
Affected Systems
The vulnerability affects the WordPress WP Accessibility Helper (WAH) plugin developed by Alex Volkov. All releases up to and including 0.6.6 are impacted. Any WordPress installation that has the plugin installed in a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate complexity and lower overall impact. The EPSS score of less than 1% reflects a very low probability of real‑world exploitation at the time of this analysis. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by delivering a forged HTTP request from a malicious webpage that a target authenticated user will load, leveraging the acquired user privileges to perform plugin actions.
OpenCVE Enrichment