Impact
The vulnerability is a missing authorization flaw that permits arbitrary code execution. An attacker can send crafted requests to the Thim Core plugin’s endpoints and trigger the execution of arbitrary code with the privileges of the web server, compromising confidentiality, integrity, and availability of the site.
Affected Systems
The flaw affects the Thim Core WordPress plugin from its earliest release up through version 2.3.3, inclusive. All users who have installed any version of the plugin prior to 2.3.4 are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation on record. Because the issue stems from missing authorization, it is inferred that unauthenticated or low‑privilege authenticated users could exploit the flaw by targeting the plugin’s administrative interfaces. If successfully leveraged, the attacker could run arbitrary code on the affected WordPress installation.
OpenCVE Enrichment