AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66642

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

WP Umbrella versions up to 2.26.2 are vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of authenticated users. Organizations using this plugin should prioritize remediation to mitigate potential exploitation that could compromise user accounts or lead to unauthorized changes.

CVE
CVE-2026-66642
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.