VYPR
Medium severity4.3NVD Advisory· Published May 25, 2026

CVE-2026-24597

CVE-2026-24597

Description

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery.

This issue affects Organization chart: from n/a through 1.7.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WordPress Organization chart plugin up to 1.7.5 allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in the Organization chart plugin by WpDevArt for WordPress, versions from n/a through 1.7.5. The plugin fails to validate or sanitize requests, allowing an attacker to craft malicious requests that, when triggered by a privileged user, perform unintended actions. [1]

Exploitation

An attacker can craft a malicious link or form and trick a logged-in administrator or other privileged user into clicking it. No authentication is required for the attacker, but the victim must be authenticated and have sufficient privileges. The attacker does not need any special network position beyond being able to deliver the malicious payload (e.g., via email, social engineering, or embedding on a site). [1]

Impact

Successful exploitation allows the attacker to force the victim to perform actions under their current authentication, such as changing plugin settings, adding or deleting data, or other administrative actions. The impact is limited to the privileges of the victim user. [1]

Mitigation

The vulnerability is fixed in version 1.7.6, released on an unknown date but referenced in the Patchstack advisory. Users should update to 1.7.6 or later. If unable to update, consider disabling the plugin or implementing additional CSRF protections. The vulnerability is not listed on CISA's KEV as of the publication date. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.