plugin

Wp Accessibility Helper Vulnerabilities

11 known security issues reported for the Wp Accessibility Helper WordPress plugin. Most recent disclosed Jul 22, 2026.

6 medium

Running Wp Accessibility Helper on your site? Check whether your installed version is affected.

Scan your site free

WP Accessibility Helper (WAH) <= 0.6.6 - Cross-Site Request Forgery

medium

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request gran...

CVSS:
4.3
Affected:
up to 0.6.6
Fix:
No patched version reported
Disclosed:
Jul 22, 2026

CVE-2026-24537 on NVD →

WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.5

unknown

[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4.

Affected:
up to 0.6.2.5
Fixed in:
0.6.2.5
Disclosed:
Dec 13, 2024

CVE-2023-41869 on NVD →

WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.3

unknown

[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.9.

Affected:
up to 0.6.3
Fixed in:
0.6.3
Disclosed:
Nov 1, 2024

CVE-2024-37926 on NVD →

WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.9

unknown

[en] The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attack...

Affected:
up to 0.6.2.9
Fixed in:
0.6.2.9
Disclosed:
Aug 29, 2024

CVE-2024-5987 on NVD →

WP Accessibility Helper <= 0.6.2.8 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update

medium

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers,...

CVSS:
5.4
Affected:
up to 0.6.2.8
Fixed in:
0.6.2.9
Disclosed:
Aug 28, 2024

CVE-2024-5987 on NVD →

WP Accessibility Helper (WAH) <= 0.6.2.9 - Missing Authorization

medium

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wah_update_image_alt() function in all versions up to, and including, 0.6.2.9. This makes it possible for unauthenticated attackers to update image alts.

CVSS:
5.3
Affected:
up to 0.6.2.9
Fixed in:
0.6.3
Disclosed:
Jul 9, 2024

CVE-2024-37926 on NVD →

WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.2.6

unknown

[en] Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5.

Affected:
up to 0.6.2.6
Fixed in:
0.6.2.6
Disclosed:
Jun 9, 2024

CVE-2024-31423 on NVD →

WP Accessibility Helper (WAH) <= 0.6.2.5 - Missing Authorization

medium

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_attachment_alt() function in versions up to, and including, 0.6.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to up...

CVSS:
4.3
Affected:
up to 0.6.2.5
Fixed in:
0.6.2.6
Disclosed:
Apr 10, 2024

CVE-2024-31423 on NVD →

WP Accessibility Helper (WAH) <= 0.6.2.4 - Missing Authorization via AJAX action

medium

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missing capability check on the wah_update_attachment_title function in versions up to, and including, 0.6.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 0.6.2.4
Fixed in:
0.6.2.5
Disclosed:
Sep 5, 2023

CVE-2023-41869 on NVD →

WP Accessibility Helper <= 0.6.0.6 - Reflected Cross-Site Scripting via wahi

medium

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 0.6.0.7
Fixed in:
0.6.0.7
Disclosed:
Jun 20, 2022

CVE-2022-0150 on NVD →

WP Accessibility Helper (WAH) [wp-accessibility-helper] < 0.6.0.7

unknown

[en] The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 0.6.0.7
Fixed in:
0.6.0.7
Disclosed:
Feb 28, 2022

CVE-2022-0150 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database