What is CVE-2026-24537?
CVE-2026-24537 is an Unauthenticated Cross Site Request Forgery (CSRF) vulnerability in WP Accessibility Helper (WAH) versions up to 0.6.6. This flaw allows an attacker to trick a user into executing unintended actions. It is recommended to update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-24537, WP Accessibility Helper (WAH) plaginin 0.6.6 və əvvəlki versiyalarında autentifikasiya olunmamış Cross Site Request Forgery (CSRF) zəifliyidir. Bu, təcavüzkara istifadəçinin xəbəri olmadan müəyyən əmrləri icra etdirməyə imkan verir. Plaginin mümkün qədər tez yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which plugin and versions are affected by CVE-2026-24537?
CVE-2026-24537 is an Unauthenticated CSRF vulnerability affecting WP Accessibility Helper (WAH) versions up to 0.6.6.
How can I protect against CVE-2026-24537?
It is recommended to update the WP Accessibility Helper (WAH) plugin to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.