A vulnerability categorized as critical has been discovered in webocoders Udimi Tools Plugin up to 3.2 on WordPress. Impacted is the function
ajax_disconnect/ajax_connect. The manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-7456. The attack can be executed remotely. There is not any exploit available.