A vulnerability categorized as critical has been discovered in webocoders Udimi Tools Plugin up to 3.2 on WordPress. Impacted is the function ajax_disconnect/ajax_connect. The manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-7456. The attack can be executed remotely. There is not any exploit available.