
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32428 is a Missing Authorization vulnerability in the Ays Pro Popup Like box WordPress plugin (ays-facebook-popup-likebox). It allows unauthenticated network-based attackers to exploit incorrectly configured access control security levels, resulting in unauthorized integrity impacts. All versions from n/a through 3.7.7 are affected. The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive actions. Because no authentication or capability checks are enforced on the affected endpoints, any unauthenticated remote attacker can trigger restricted functionality over the network with low attack complexity and no user interaction required. The vulnerability is categorized under the broader pattern of exploiting incorrectly configured access control security levels (Feedly, Patchstack).
Successful exploitation results in a low-level integrity impact on the affected WordPress site, with no direct confidentiality or availability consequences per the CVSS scoring. An unauthenticated attacker could manipulate plugin-controlled data or settings (such as popup configurations) without authorization. While the immediate impact is limited, unauthorized modification of plugin settings could be leveraged to display malicious content to site visitors or as a stepping stone in a broader attack chain (Feedly).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.017%, indicating a currently low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known public PoC exploit code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Feedly).
Users should update the Popup Like box plugin to a version beyond 3.7.7 as soon as a patched release is made available by Ays Pro. In the interim, site administrators should consider deactivating or removing the plugin if it is not critical to site operations. Restricting access to WordPress admin and plugin endpoints via web application firewall (WAF) rules can provide an additional layer of defense (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."