SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-24537

MEDIUM · CVSS 4.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The WP Accessibility Helper (WAH) versions up to 0.6.6 are vulnerable to an unauthenticated Cross Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of a user without their consent. This vulnerability poses a medium risk, particularly for website administrators and developers using the affected plugin, who should prioritize applying updates or mitigating measures to protect their sites from potential exploitation.

CVE
CVE-2026-24537
Severity
MEDIUM
CVSS
4.3
EPSS
0.11%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.