Executive brief
WP Accessibility Helper (WAH) is a WordPress plugin designed to help website owners make their content more accessible to users with disabilities. A security flaw in versions 0.6.6 and earlier allows an attacker to trick a site administrator into performing unintended actions, such as changing plugin settings, by clicking a malicious link. This could lead to unauthorized configuration changes that impact the website's accessibility features or layout.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Accessibility Helper (WAH) plugin for WordPress (versions <= 0.6.6) due to a lack of proper nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to perform unauthorized state-changing actions, such as modifying plugin configurations, under the security context of the authenticated user. As of the advisory date, no official patch has been confirmed.
Affected products
- Alex Volkov WP Accessibility Helper (WAH) <= 0.6.6
Timeline
- 2025-12-26: disclosed: Reported by Trương Hữu Phúc via Patchstack
- 2026-07-22: advisory: Patchstack published the vulnerability details
- 2026-07-23: other: CVE record published to NVD dataset