CVE-2026-32560: WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion vulnerability
Published Aug 24, 2026
·Updated
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
Affected Software
1 affected component
WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator<=1.4
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs subscriber-level access to a WordPress site using an affected MagicAI for WordPress plugin version. No user interaction is required.
2
What impact could successful exploitation have?
The vulnerability is rated high severity with high confidentiality, integrity, and availability impact. It could allow local file inclusion through the affected plugin.
3
Which plugin versions are affected?
MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator versions 1.4 and earlier are affected.