Impact
The ThumbPress plugin before version 6.2.2 contains an AJAX action that can deactivate the plugin without performing a capability check (CWE‑862). An authenticated user with at least Subscriber permissions can exploit this flaw, causing the plugin to be disabled and thereby interrupting the site's image handling features. The vulnerability does not allow arbitrary code execution, but it does permit an attacker to deny service by removing a critical component of the site.
Affected Systems
All WordPress sites running the ThumbPress plugin older than 6.2.2 are susceptible. The flaw applies regardless of other plugins or themes, and any user with Subscriber or higher privileges can trigger it.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate and obtain at least Subscriber-level permissions; from there the missing capability check allows them to call the AJAX endpoint and deactivate the plugin. The flaw does not enable escalation beyond the authenticated user, but it can cause significant functional disruption to the site.
OpenCVE Enrichment