Executive brief
MagicAI for WordPress is a popular plugin that enables AI-powered text, image, chat, and code generation for website administrators and content creators. A local file inclusion vulnerability in versions 1.4 and earlier allows authenticated users with subscriber-level privileges to read sensitive files from the web server, potentially exposing database credentials, configuration secrets, and other confidential data that could lead to site takeover.
Technical details
This is a local file inclusion (LFI) vulnerability requiring subscriber-level authentication to exploit. The vulnerability exists in MagicAI for WordPress versions 1.4 and earlier, affecting the plugin's AI generator functionality. An authenticated attacker with subscriber privileges can craft requests to read arbitrary server files without proper path validation. The attack vector is network-based and does not require additional user interaction beyond authentication. Successful exploitation allows attackers to access sensitive configuration files, database credentials, and other system files that may lead to further site compromise or administrative account takeover. As of the advisory date, no official patch has been released; Patchstack has provided a mitigation rule to block exploitation attempts.
Affected products
- MagicAI MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4
Timeline
- 2026-08-24: disclosed: CVE-2026-32560 published on NVD and Patchstack
- 2026-06-28: reported: Vulnerability reported by Jamaal ahmed