AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-7456

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Udimi Tools plugin for WordPress is vulnerable due to a lack of capability checks in the `ajax_disconnect()` and `ajax_connect()` functions, affecting all versions up to 3.2. This vulnerability allows authenticated attackers with Subscriber-level access or higher to delete critical configuration options or overwrite them with malicious data, potentially compromising the site's connection to its Udimi account. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized data modification.

CVE
CVE-2026-7456
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
WordPress

Original NVD Description

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.