Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery.

This issue affects WP Umbrella: from 2.24.2 through 2.26.2.
Published: 2026-08-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Umbrella plugin contains a CSRF flaw that allows an attacker to initiate privileged actions on behalf of an authenticated user, such as changing settings, posting content, or performing administrative operations, thereby compromising the site’s integrity. This weakness is identified as CWE-352.

Affected Systems

The flaw affects the WordPress WP Umbrella plugin up to version 2.26.2, installed on any WordPress site. Sites running these vulnerable plugin versions are susceptible, as the plugin is provided by the vendor WP Umbrella.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector, based on the description, is that an attacker may send a malicious link to a logged‑in user that triggers a state‑changing request; once the request is executed, the attacker could manipulate site configuration or content.

Generated by OpenCVE AI on August 10, 2026 at 13:27 UTC.

Remediation

Vendor Solution

Update the WordPress WP Umbrella Plugin to the latest available version (at least 2.27.0).


OpenCVE Recommended Actions

  • Upgrade the WP Umbrella plugin to version 2.27.0 or later.
  • If the upgrade is not immediately feasible, temporarily disable the plugin until a patch is applied to mitigate CSRF risk.
  • Review recent configuration changes and content for evidence of unauthorized activity and restore from backup if necessary.

Generated by OpenCVE AI on August 10, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from n/a through 2.26.2. Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.
Title WordPress WP Umbrella plugin <= 2.26.2 - Cross Site Request Forgery (CSRF) vulnerability WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF) vulnerability
References

Mon, 10 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from n/a through 2.26.2.
Title WordPress WP Umbrella plugin <= 2.26.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-10T11:30:44.610Z

Reserved: 2026-07-27T14:00:34.307Z

Link: CVE-2026-66642

cve-icon Vulnrichment

Updated: 2026-08-10T10:57:34.178Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T13:30:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)