VYPR
Medium severity5.4NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32420

CVE-2026-32420

Description

Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: from n/a through <= 7.6.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in GamiPress up to 7.6.6 allows attackers to force privileged users to execute unintended actions.

The GamiPress plugin for WordPress (versions up to and including 7.6.6) contains a Cross-Site Request Forgery (CSRF) vulnerability. This issue arises from insufficient validation of requests, allowing an attacker to trick an authenticated administrator (or other privileged user) into performing unwanted actions while their session is active [1].

Exploitation requires user interaction: the victim must click a malicious link, visit a crafted page, or submit a form. No direct authentication is needed for the attacker, but the target must be logged into the site with sufficient privileges. This is typical of CSRF attacks, which leverage the victim's active session to forge requests [1].

If successfully exploited, an attacker can force the victim to execute actions under their current authentication, such as changing settings, modifying user roles, or performing other administrative operations. The CVSS score of 5.4 (Medium) reflects the requirement for user interaction and the potential for limited impact [1].

The vulnerability has been patched in GamiPress version 7.6.7. Users are advised to update immediately. For those unable to update, contacting the hosting provider or web developer for assistance is recommended. The patch is available via the WordPress plugin repository, and auto-updates are suggested for Patchstack users [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.