WP Accessibility Helper (WAH)
WP Accessibility Helper (WAH) has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 3 disclosures.
The most common weakness is Missing Authorization, behind 4 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.
Every one of the 6 issues recorded for WP Accessibility Helper (WAH) has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by Kévin Mosbahi (Mika). WP Accessibility Helper (WAH) is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-0150WP Accessibility Helper <= 0.6.0.6 - Reflected Cross-Site Scripting via wahi
Read the full analysisVulnerability Records

WP Accessibility Helper (WAH)
Author
Alex Volkov
WordPress Accessibility made easy! Web accessibility refers to the inclusive practice of removing barriers that prevent interaction with, or access to websites, by people with disabilities. When sites are correctly designed, developed and edited, all users have equal access to information and functionality. WP Accessibility Helper helps solve accessibility problems like font size, contrast, titles and aria-label tags, images alt and more. Official website English version: https://accessibility-helper.co.il/ Hebrew version: https://accessibility-helper.co.il/il/ Privacy terms WAH free uses cookies to save contrast variation colors selected by user We are using cookies for internal usage only and never provide this data to the third party organizations/companies
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C