Impact
The ThumbPress WordPress plugin before version 6.5 suffers from an unauthenticated broken access control flaw. Attackers can bypass normal permission checks to access or modify plugin features and data. This flaw may enable the theft or alteration of image settings, database records, or other sensitive configuration information, thereby compromising confidentiality and integrity of site content. The weakness is identified as a missing authorization check (CWE-862).
Affected Systems
The vulnerability affects installations of Codexpert, Inc’s ThumbPress plugin for WordPress running any version earlier than 6.5. Any site that has that plugin active, regardless of the user’s authentication state, is impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Since the flaw allows unauthenticated access to privileged plugin functions, the attack vector is likely via direct HTTP requests to protected endpoints or using manipulated URLs – a typical web application exploitation scenario. No additional conditions are stated in the advisory, so a successful exploit is considered straightforward if the plugin is present.
OpenCVE Enrichment