Description
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Published: 2026-08-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Cwicly WordPress plugin permits an attacker to execute arbitrary code on the hosting server. The flaw arises from improper handling of contributor input, allowing malicious code injection into files or modules that are subsequently executed by the server. Consequently, an attacker can gain full control over the compromised site, leading to data theft, defacement, or further attacks against the server infrastructure. This weakness is identified as CWE-94, which denotes a code injection vulnerability.

Affected Systems

The affected software is the Cwicly plugin for WordPress, with all versions up to and including 1.4.4. Administrators of WordPress sites who have installed and enabled this plugin are at risk.

Risk and Exploitability

The CVSS score of 9.9 marks this issue as Critical, indicating that exploitation would result in complete compromise of confidentiality, integrity, and availability. The EPSS score is not available, so the likelihood of exploitation is unknown, but the severity and lack of mitigation in the vendor’s response mean that attackers can target sites without much difficulty. This vulnerability can be exploited remotely through a WordPress site that allows contributor access; in that scenario, an authenticated contributor could submit malicious payloads that are executed during normal operation. The issue has not been listed in CISA's KEV catalog, but its high severity warrants immediate attention.

Generated by OpenCVE AI on August 18, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cwicly plugin to the latest available version (1.4.5 or newer).
  • If a patch is not yet available, temporarily deactivate or remove the Cwicly plugin from the WordPress installation until a fix is released.
  • Restrict WordPress contributor roles to trusted users only, or remove the contributor capability altogether if not required.

Generated by OpenCVE AI on August 18, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Title WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T13:59:11.395Z

Reserved: 2026-03-12T11:11:35.694Z

Link: CVE-2026-32444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T14:17:03.263

Modified: 2026-08-18T14:17:03.263

Link: CVE-2026-32444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')