
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32438 is a Missing Authorization vulnerability in the VW School Education WordPress theme developed by vowelweb. It allows unauthenticated network attackers to exploit incorrectly configured access control security levels, resulting in unauthorized data modification. The vulnerability affects VW School Education versions from n/a through 1.4.6. It was published on March 13, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the theme fails to properly verify whether a requesting user has the necessary permissions before executing certain actions. An unauthenticated remote attacker can send crafted network requests to exploit misconfigured access control checks within the theme, bypassing authorization gates entirely. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network (Feedly).
Successful exploitation allows an unauthenticated attacker to perform unauthorized data modifications on WordPress sites running the affected theme, compromising data integrity. Confidentiality and availability are not directly impacted according to the CVSS assessment, but unauthorized write access could be leveraged to alter site content, inject malicious material, or escalate further within the WordPress environment (Feedly).
The vulnerability requires no authentication and no user interaction, making it accessible to any remote attacker. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of active exploitation in the wild. No evidence of in-the-wild exploitation, threat actor attribution, exploit kits, or CISA KEV catalog listing has been reported at this time (Feedly).
Users running VW School Education theme version 1.4.6 or earlier should update to a patched version as soon as one becomes available from the vowelweb developer. In the interim, site administrators should consider deactivating the theme if it is not critical, or implementing a web application firewall (WAF) rule to restrict unauthorized access to sensitive theme endpoints. Monitoring WordPress access logs for unexpected unauthenticated POST requests to theme-specific action handlers is also advisable (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."