CVE-2026-32488

HIGH

WordPress User Registration plugin <= 4.4.9 - Privilege Escalation vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-32488. PoCs published by izxci, webshellseo8.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2026-32488, demonstrating an authentication bypass or user registration vulnerability in a WordPress plugin via a crafted POST request to admin-ajax.php with a manipulated nonce and form data.

Description

Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.

Exploits (2)

github WORKING POC
by izxci · poc
https://github.com/izxci/CVE-2026-32488

This repository contains a functional exploit PoC for CVE-2026-32488, demonstrating an authentication bypass or user registration vulnerability in a WordPress plugin via a crafted POST request to admin-ajax.php with a manipulated nonce and form data.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress (specific plugin not specified)
No auth needed
Prerequisites: valid nonce value · access to WordPress admin-ajax.php endpoint
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →
nomisec SUSPICIOUS
by webshellseo8 · poc
https://github.com/webshellseo8/CVE-2026-32488-POC

The repository claims to be an auto-exploit and mass scanner for CVE-2026-32488 targeting UpdraftPlus but lacks actual exploit code. It directs users to external contacts (Telegram, website) and uses vague marketing language without technical details.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: UpdraftPlus WordPress plugin
No auth needed
Prerequisites: target list in a text file
mistral-large-3 · analyzed Jun 16, 2026 Full analysis →

Scores

CVSS v3 8.1
EPSS 0.0034
EPSS Percentile 27.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
wpeverest/User Registration < <= 4.4.9
Published Mar 25, 2026
Tracked Since Mar 25, 2026