CVE-2026-32444: WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability
Published Aug 18, 2026
·Updated
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Affected Software
1 affected component
WordPress Cwicly plugin<=1.4.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Cwicly pluginto a version that resolves this vulnerability.Fixed in 1.4.4
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which sites and users are exposed?
Sites using Cwicly version 1.4.4 or earlier are affected. Exploitation requires an account with the WordPress Contributor role or equivalent privileges.
2
What does an attacker need to exploit this issue?
The vulnerability has network attack vector, low attack complexity, no user interaction requirement, and can affect confidentiality, integrity, and availability beyond the vulnerable component. An authenticated Contributor could execute code remotely.