MEDIUMCVSS 6.5Vulnerability

CVE-2026-7456

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.

Properties

severity
MEDIUM
cvss_severity
MEDIUM
cvss_score
6.5
epss_score
0.0044
retrieved_at
2026-10-02T19:34:42+00:00
last_source
FIRST EPSS
score
6.5
cve_id
CVE-2026-7456
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-05T14:17:14.960
last_modified
2026-08-12T21:00:37.147
epss_percentile
0.35935

Related Entities (3)

ENRICHED_BY (1)

→[Source]FIRST EPSS

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7456 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal