Impact
The WP Umbrella plugin contains a CSRF flaw that allows an attacker to initiate privileged actions on behalf of an authenticated user, such as changing settings, posting content, or performing administrative operations, thereby compromising the site’s integrity. This weakness is identified as CWE-352.
Affected Systems
The flaw affects the WordPress WP Umbrella plugin up to version 2.26.2, installed on any WordPress site. Sites running these vulnerable plugin versions are susceptible, as the plugin is provided by the vendor WP Umbrella.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector, based on the description, is that an attacker may send a malicious link to a logged‑in user that triggers a state‑changing request; once the request is executed, the attacker could manipulate site configuration or content.
OpenCVE Enrichment