CVE-2026-66642
Received Received - Intake

Cross-Site Request Forgery in WP Umbrella

Vulnerability report for CVE-2026-66642, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Patchstack

Description

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_umbrella wp_umbrella From 2.24.2 (inc) to 2.26.2 (inc)
wp_umbrella wp_umbrella 2.27.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Umbrella WordPress plugin affecting versions up to 2.26.2. It allows attackers to trick authenticated users into executing unwanted actions by leveraging their active session. Exploitation requires user interaction, such as clicking a malicious link or submitting a form.

Detection Guidance

Detecting CSRF vulnerabilities typically involves checking for outdated versions of the WP Umbrella plugin. Use commands like 'wp plugin list' in WordPress CLI to verify the installed version. If the version is between 2.24.2 and 2.26.2, the system is vulnerable.

Impact Analysis

An attacker could perform actions on your behalf, such as changing settings, installing plugins, or modifying content, if you are logged in as a privileged user and click a malicious link. This could lead to unauthorized changes in your WordPress site.

Compliance Impact

This CSRF vulnerability could potentially lead to unauthorized administrative actions, such as creating new admin accounts, which may violate compliance requirements for data protection and access control under standards like GDPR and HIPAA. Unauthorized access could result in data breaches or improper handling of sensitive information.

Mitigation Strategies

Immediately update the WP Umbrella plugin to version 2.27.0 or later. Enable auto-updates for the plugin if available. Review user accounts for unauthorized changes and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66642. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart