First GreenHat public CVE record
CVE-2026-66642
Cross-site request forgery in the WP Umbrella WordPress plugin
The published record identifies a cross-site request forgery vulnerability affecting WP Umbrella versions 2.24.2 through 2.26.2. The vendor explains that exploitation required a logged-in WordPress administrator to visit a malicious page.
Disclosure timeline
Reported to Patchstack
Anthony Green's report entered Patchstack's managed disclosure process.
Vendor independently finds and fixes the issue
WP Umbrella says its internal audit separately found and fixed the issue before the report reached its team.
Patch and CVE published
WP Umbrella 2.27.0 and the coordinated public CVE record were released.
The vendor describes its internal discovery as independent of the external report. The official CVE record credits Anthony Green [Antnation] as the finder.
Update guidance
Update WP Umbrella to version 2.27.0 or later.
What defenders can carry forward
Security checks should validate the route the application resolved, rather than trusting a matching string found elsewhere in the raw request URL.
- Class
- Cross-Site Request Forgery (CSRF)
- Weakness
- CWE-352
- Affected
- 2.24.2–2.26.2
- Fixed
- 2.27.0 or later
- Reported
- Published
- CNA
- Patchstack
- Credited finder
- Anthony Green [antnation]
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Primary records
