
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32420 is a Cross-Site Request Forgery (CSRF) vulnerability in the GamiPress WordPress plugin developed by Ruben Garcia. It affects all versions of GamiPress through 7.6.6 and allows network-based attackers to trigger unintended actions on behalf of authenticated users. The vulnerability was published on March 13, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate the origin of state-changing HTTP requests. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user, silently submits a forged request to the GamiPress plugin on their behalf. Exploitation requires no privileges on the part of the attacker but does require user interaction — specifically, an authenticated victim must be tricked into visiting a malicious URL or page. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation can result in low-severity impacts to both data integrity and availability, as an attacker could manipulate GamiPress plugin settings or data (such as points, achievements, or ranks) without the victim's knowledge. Confidentiality is not directly impacted. The scope is limited to the affected WordPress installation, with no evidence of lateral movement potential beyond the plugin's functionality (Feedly).
There is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog at this time. The EPSS score is extremely low at approximately 0.008%, indicating a very low probability of exploitation in the near term. No exploit kits or weaponized code have been publicly identified (Feedly).
/wp-content/plugins/gamipress/readme.txt./wp-admin/admin-ajax.php with GamiPress-specific action parameters) from unusual referrer URLs or external domains.Users should update the GamiPress plugin to a version newer than 7.6.6, which includes the CSRF fix. As a general WordPress hardening measure, administrators should ensure that only trusted users have access to authenticated sessions and consider using a Web Application Firewall (WAF) capable of detecting CSRF patterns. No specific configuration-based workaround has been published; upgrading is the recommended remediation (Patchstack, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."