GHSA-fjcf-648f-mmhxMediumCVSS 6.5

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a...

Published
August 5, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_disconnect() function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion ajax_connect() handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.

🔗 References (9)