
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32527 is a Missing Authorization (Broken Access Control) vulnerability in the CRM Perks plugin WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms for WordPress. It affects all plugin versions up to and including 1.1.5, and was patched in version 1.1.6. The vulnerability was reported by researcher Nabil Irawan on January 28, 2026, and published by Patchstack on March 20, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing a privileged action. An authenticated attacker with low privileges (e.g., Subscriber role) can exploit this flaw over the network without user interaction, by invoking plugin functionality that should be restricted to higher-privileged users. The root cause is a missing or improperly implemented authorization/nonce check in one or more plugin functions that interface with the Insightly CRM integration (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker (Subscriber-level or above) to access data or perform actions beyond their intended authorization level. The primary impact is a high confidentiality risk — attackers may be able to read sensitive CRM data (e.g., Insightly contact records, form submission data) that should be restricted to administrators. Integrity and availability are not directly impacted according to the CVSS assessment (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
/wp-content/plugins/cf7-insightly/readme.txt.admin-ajax.php) that lack proper capability checks.wp-admin/admin-ajax.php with plugin-specific action parameters from low-privilege user accounts; repeated requests to plugin REST API endpoints from unexpected IP addresses.cf7-insightly plugin; anomalous access patterns (high frequency, off-hours) from authenticated low-privilege sessions./wp-content/plugins/cf7-insightly/.The vendor (CRM Perks) has released a patched version: update to WP Insightly version 1.1.6 or later immediately. Site administrators who cannot update immediately should consider temporarily deactivating the plugin or restricting site registration to prevent low-privilege account creation. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated (Patchstack).
The vulnerability was discovered and disclosed by security researcher Nabil Irawan through Patchstack's coordinated disclosure process. Patchstack classified it as medium priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."