Junglewise Threat Intelligence

CVE-2026-24537: Alex Volkov WP Accessibility Helper CSRF

CVE-2026-24537 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

WP Accessibility Helper (WAH) is a WordPress plugin designed to help website owners make their content more accessible to users with disabilities. A security flaw in versions 0.6.6 and earlier allows an attacker to trick a site administrator into performing unintended actions, such as changing plugin settings, by clicking a malicious link. This could lead to unauthorized configuration changes that impact the website's accessibility features or layout.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Accessibility Helper (WAH) plugin for WordPress (versions <= 0.6.6) due to a lack of proper nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to perform unauthorized state-changing actions, such as modifying plugin configurations, under the security context of the authenticated user. As of the advisory date, no official patch has been confirmed.

Affected products

  • Alex Volkov WP Accessibility Helper (WAH) <= 0.6.6

Timeline

  • 2025-12-26: disclosed: Reported by Trương Hữu Phúc via Patchstack
  • 2026-07-22: advisory: Patchstack published the vulnerability details
  • 2026-07-23: other: CVE record published to NVD dataset

References