MEDIUMCVSS 6.5Vulnerability
CVE-2026-7456
The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.
Properties
- severity
- MEDIUM
- cvss_severity
- MEDIUM
- cvss_score
- 6.5
- epss_score
- 0.0044
- retrieved_at
- 2026-10-02T19:34:42+00:00
- last_source
- FIRST EPSS
- score
- 6.5
- cve_id
- CVE-2026-7456
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- published_at
- 2026-08-05T14:17:14.960
- last_modified
- 2026-08-12T21:00:37.147
- epss_percentile
- 0.35935
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
Explore deeper with Ninja Signal's threat intelligence graph