
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32344 is a Cross-Site Request Forgery (CSRF) vulnerability in the Corpiva WordPress theme developed by desertthemes. It affects all versions of the Corpiva theme up to and including version 1.0.96, and was discovered by researcher Trương Hữu Phúc (truonghuuphuc) and reported on January 12, 2026, with public disclosure on February 11, 2026 via Patchstack. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), arising from insufficient or absent CSRF token validation in the Corpiva WordPress theme. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated privileged user (e.g., a WordPress administrator), causes the victim's browser to submit unauthorized requests to the WordPress site on their behalf. Exploitation requires user interaction — specifically, a privileged user must be tricked into clicking a malicious link or visiting a crafted page while authenticated (Patchstack).
Successful exploitation allows a malicious actor to force higher-privileged users (such as site administrators) to execute unwanted actions on the WordPress site without their knowledge or consent. The primary impact is on integrity — an attacker could trigger unauthorized configuration changes, content modifications, or administrative actions. Confidentiality and availability are not directly impacted according to the CVSS assessment (Patchstack).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-32344. The EPSS score is extremely low at approximately 0.008%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, though this specific vulnerability is rated low priority (Patchstack).
The vulnerability is patched in Corpiva theme version 1.0.97. Site owners should update the Corpiva theme to version 1.0.97 or later immediately. If an immediate update is not possible, site administrators should avoid clicking on unsolicited links while logged into the WordPress admin panel, and consider using a WordPress security plugin (such as Patchstack) that provides virtual patching capabilities (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."