Unauthorized Data Modification in Udimi Tools Plugin for WordPress
CVE-2026-7456
6.5MEDIUM
What is CVE-2026-7456?
The Udimi Tools plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check on the ajax_disconnect() function. This vulnerability affects all versions up to and including 3.2. Authenticated attackers, even those with low-level Subscriber access, can exploit this issue to delete crucial configuration options such as the API key and user email linked to the Udimi account. Furthermore, the ajax_connect() handler similarly lacks necessary checks, enabling attackers to overwrite these settings with their own API key, resulting in a significant security breach for affected sites.
Affected Version(s)
Udimi Tools 0 <= 3.2