Description
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Cwicly WordPress plugin permits an attacker to execute arbitrary code on the hosting server. The flaw arises from improper handling of contributor input, allowing malicious code injection into files or modules that are subsequently executed by the server. Consequently, an attacker can gain full control over the compromised site, leading to data theft, defacement, or further attacks against the server infrastructure. This weakness is identified as CWE-94, which denotes a code injection vulnerability.

Affected Systems

The affected software is the Cwicly plugin for WordPress, with all versions up to and including 1.4.4. Administrators of WordPress sites who have installed and enabled this plugin are at risk.

Risk and Exploitability

The CVSS score of 9.9 marks this issue as Critical, indicating that exploitation would result in complete compromise of confidentiality, integrity, and availability. The EPSS score is not available, so the likelihood of exploitation is unknown, but the severity and lack of mitigation in the vendor’s response mean that attackers can target sites without much difficulty. This vulnerability can be exploited remotely through a WordPress site that allows contributor access; in that scenario, an authenticated contributor could submit malicious payloads that are executed during normal operation. The issue has not been listed in CISA's KEV catalog, but its high severity warrants immediate attention.

Generated by OpenCVE AI on August 18, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cwicly plugin to the latest available version (1.4.5 or newer).
  • If a patch is not yet available, temporarily deactivate or remove the Cwicly plugin from the WordPress installation until a fix is released.
  • Restrict WordPress contributor roles to trusted users only, or remove the contributor capability altogether if not required.

Generated by OpenCVE AI on August 18, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Cwicly
Cwicly cwicly
Wordpress
Wordpress wordpress
Vendors & Products Cwicly
Cwicly cwicly
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Title WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cwicly Cwicly
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T21:25:43.571Z

Reserved: 2026-03-12T11:11:35.694Z

Link: CVE-2026-32444

cve-icon Vulnrichment

Updated: 2026-08-18T19:40:30.413Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T14:17:03.263

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-32444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:57Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')