Remote Code Execution in Cwicly Plugin for WordPress
CVE-2026-32444

9.9CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-32444?

A remote code execution vulnerability exists in versions of the Cwicly WordPress plugin prior to 1.4.4. This flaw allows unauthorized users to execute arbitrary code on the server, potentially compromising the website's security and integrity. It is critical for WordPress site administrators to update their Cwicly installations to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Cwicly <= 1.4.4

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johska | Patchstack Bug Bounty Program
.