CVE-2026-66642: WordPress WP Umbrella plugin <= 2.26.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Aug 10, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery.
This issue affects WP Umbrella: from n/a through 2.26.2.
Affected Software
1 affected component
WordPress WP Umbrella<=2.26.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Umbrella pluginto a version that resolves this vulnerability.Fixed in 2.27.0
Event History
Aug 10, 2026
CVE Published
via MITRE·10:07 AM
Data Sourced
via MITRE·10:07 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66642?
CVE-2026-66642 has a medium severity rating of 5.4.
2
How do I fix CVE-2026-66642?
To address CVE-2026-66642, update the WP Umbrella plugin to version 2.26.3 or later.
3
What type of vulnerability is described in CVE-2026-66642?
CVE-2026-66642 describes a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of WP Umbrella are affected by CVE-2026-66642?
CVE-2026-66642 affects all versions of WP Umbrella up to and including 2.26.2.
5
What impact does CVE-2026-66642 have on WordPress sites?
CVE-2026-66642 can allow attackers to perform actions on behalf of authenticated users without their consent.