Junglewise Threat Intelligence

CVE-2026-32444: Cwicly Contributor Remote Code Execution

CVE-2026-32444 · Severity: critical · CVSS 9.9 · Published 2026-08-18

Executive brief

Cwicly is a WordPress plugin used to build and customize website pages. A vulnerability in version 1.4.4 and earlier allows users with Contributor-level permissions to execute arbitrary code on the web server, potentially compromising the entire website and any data stored on it. This affects WordPress sites using the vulnerable plugin.

Technical details

This is a remote code execution vulnerability in the Cwicly WordPress plugin that requires Contributor-level privileges to exploit. The vulnerability class is injection (OWASP A3), allowing authenticated attackers with Contributor role to execute arbitrary commands on the affected server. The attack vector is network-based and requires valid WordPress credentials with Contributor privileges. An attacker can achieve full code execution on the server, potentially leading to complete site compromise, data theft, and malware installation. No official patch was available as of the advisory date (17 Aug 2026), though mitigation rules have been issued by Patchstack.

Affected products

  • Cwicly Cwicly <= 1.4.4

Timeline

  • 2026-08-17: disclosed
  • 2026-08-18: advisory

References