WP Accessibility Helper (WAH) <= 0.6.6 - Cross-Site Request Forgery
medium
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 0.6.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-24537 on NVD →
WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.5
unknown
[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4.
- Affected:
- up to 0.6.2.5
- Fixed in:
- 0.6.2.5
- Disclosed:
- Dec 13, 2024
CVE-2023-41869 on NVD →
WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.3
unknown
[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.9.
- Affected:
- up to 0.6.3
- Fixed in:
- 0.6.3
- Disclosed:
- Nov 1, 2024
CVE-2024-37926 on NVD →
WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.9
unknown
[en] The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attack...
- Affected:
- up to 0.6.2.9
- Fixed in:
- 0.6.2.9
- Disclosed:
- Aug 29, 2024
CVE-2024-5987 on NVD →
WP Accessibility Helper <= 0.6.2.8 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
medium
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers,...
- CVSS:
- 5.4
- Affected:
- up to 0.6.2.8
- Fixed in:
- 0.6.2.9
- Disclosed:
- Aug 28, 2024
CVE-2024-5987 on NVD →
WP Accessibility Helper (WAH) <= 0.6.2.9 - Missing Authorization
medium
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wah_update_image_alt() function in all versions up to, and including, 0.6.2.9. This makes it possible for unauthenticated attackers to update image alts.
- CVSS:
- 5.3
- Affected:
- up to 0.6.2.9
- Fixed in:
- 0.6.3
- Disclosed:
- Jul 9, 2024
CVE-2024-37926 on NVD →
WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.6
unknown
[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5.
- Affected:
- up to 0.6.2.6
- Fixed in:
- 0.6.2.6
- Disclosed:
- Jun 9, 2024
CVE-2024-31423 on NVD →
WP Accessibility Helper (WAH) <= 0.6.2.5 - Missing Authorization
medium
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_attachment_alt() function in versions up to, and including, 0.6.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to up...
- CVSS:
- 4.3
- Affected:
- up to 0.6.2.5
- Fixed in:
- 0.6.2.6
- Disclosed:
- Apr 10, 2024
CVE-2024-31423 on NVD →
WP Accessibility Helper (WAH) <= 0.6.2.4 - Missing Authorization via AJAX action
medium
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missing capability check on the wah_update_attachment_title function in versions up to, and including, 0.6.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 0.6.2.4
- Fixed in:
- 0.6.2.5
- Disclosed:
- Sep 5, 2023
CVE-2023-41869 on NVD →
WP Accessibility Helper <= 0.6.0.6 - Reflected Cross-Site Scripting via wahi
medium
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 0.6.0.7
- Fixed in:
- 0.6.0.7
- Disclosed:
- Jun 20, 2022
CVE-2022-0150 on NVD →
WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.0.7
unknown
[en] The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 0.6.0.7
- Fixed in:
- 0.6.0.7
- Disclosed:
- Feb 28, 2022
CVE-2022-0150 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database