CVE-2026-32428
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32428 is a Missing Authorization vulnerability in the Ays Pro Popup Like box WordPress plugin (ays-facebook-popup-likebox). It allows unauthenticated network-based attackers to exploit incorrectly configured access control security levels, resulting in unauthorized integrity impacts. All versions from n/a through 3.7.7 are affected. The vulnerability was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive actions. Because no authentication or capability checks are enforced on the affected endpoints, any unauthenticated remote attacker can trigger restricted functionality over the network with low attack complexity and no user interaction required. The vulnerability is categorized under the broader pattern of exploiting incorrectly configured access control security levels (Feedly, Patchstack).

Impact

Successful exploitation results in a low-level integrity impact on the affected WordPress site, with no direct confidentiality or availability consequences per the CVSS scoring. An unauthenticated attacker could manipulate plugin-controlled data or settings (such as popup configurations) without authorization. While the immediate impact is limited, unauthorized modification of plugin settings could be leveraged to display malicious content to site visitors or as a stepping stone in a broader attack chain (Feedly).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.017%, indicating a currently low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known public PoC exploit code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report (Feedly).

Mitigation and workarounds

Users should update the Popup Like box plugin to a version beyond 3.7.7 as soon as a patched release is made available by Ays Pro. In the interim, site administrators should consider deactivating or removing the plugin if it is not critical to site operations. Restricting access to WordPress admin and plugin endpoints via web application firewall (WAF) rules can provide an additional layer of defense (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management