CVE-2026-32420
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32420 is a Cross-Site Request Forgery (CSRF) vulnerability in the GamiPress WordPress plugin developed by Ruben Garcia. It affects all versions of GamiPress through 7.6.6 and allows network-based attackers to trigger unintended actions on behalf of authenticated users. The vulnerability was published on March 13, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate the origin of state-changing HTTP requests. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user, silently submits a forged request to the GamiPress plugin on their behalf. Exploitation requires no privileges on the part of the attacker but does require user interaction — specifically, an authenticated victim must be tricked into visiting a malicious URL or page. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation can result in low-severity impacts to both data integrity and availability, as an attacker could manipulate GamiPress plugin settings or data (such as points, achievements, or ranks) without the victim's knowledge. Confidentiality is not directly impacted. The scope is limited to the affected WordPress installation, with no evidence of lateral movement potential beyond the plugin's functionality (Feedly).

Exploitability

There is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog at this time. The EPSS score is extremely low at approximately 0.008%, indicating a very low probability of exploitation in the near term. No exploit kits or weaponized code have been publicly identified (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running GamiPress version 7.6.6 or earlier, which can often be detected via plugin enumeration tools or by checking publicly accessible readme files at /wp-content/plugins/gamipress/readme.txt.
  2. Craft malicious request: Construct a forged HTTP request targeting a GamiPress state-changing action endpoint (e.g., awarding points, modifying achievements) that would normally require CSRF token validation.
  3. Social engineering: Embed the forged request in a malicious webpage (e.g., as an auto-submitting HTML form) and trick an authenticated WordPress administrator or editor into visiting the page.
  4. Trigger action: When the victim loads the malicious page while authenticated to the target WordPress site, the browser automatically submits the forged request, causing the unintended GamiPress action to execute on the victim's behalf (Feedly, Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to GamiPress admin endpoints (e.g., /wp-admin/admin-ajax.php with GamiPress-specific action parameters) from unusual referrer URLs or external domains.
  • Application: Unexplained changes to GamiPress data such as unauthorized point awards, achievement unlocks, or rank modifications not correlated with legitimate user activity.
  • Network: HTTP requests to GamiPress endpoints originating from non-administrative IP addresses or with missing/invalid nonce values in the request body.

Mitigation and workarounds

Users should update the GamiPress plugin to a version newer than 7.6.6, which includes the CSRF fix. As a general WordPress hardening measure, administrators should ensure that only trusted users have access to authenticated sessions and consider using a Web Application Firewall (WAF) capable of detecting CSRF patterns. No specific configuration-based workaround has been published; upgrading is the recommended remediation (Patchstack, Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management