CyberRota Analysis
AI-GeneratedWP Umbrella versions up to 2.26.2 are vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of authenticated users. Organizations using this plugin should prioritize remediation to mitigate potential exploitation that could compromise user accounts or lead to unauthorized changes.
CVE
CVE-2026-66642
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
Original NVD Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.