Description
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ThumbPress WordPress plugin before version 6.5 suffers from an unauthenticated broken access control flaw. Attackers can bypass normal permission checks to access or modify plugin features and data. This flaw may enable the theft or alteration of image settings, database records, or other sensitive configuration information, thereby compromising confidentiality and integrity of site content. The weakness is identified as a missing authorization check (CWE-862).

Affected Systems

The vulnerability affects installations of Codexpert, Inc’s ThumbPress plugin for WordPress running any version earlier than 6.5. Any site that has that plugin active, regardless of the user’s authentication state, is impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Since the flaw allows unauthenticated access to privileged plugin functions, the attack vector is likely via direct HTTP requests to protected endpoints or using manipulated URLs – a typical web application exploitation scenario. No additional conditions are stated in the advisory, so a successful exploit is considered straightforward if the plugin is present.

Generated by OpenCVE AI on August 18, 2026 at 15:21 UTC.

Remediation

Vendor Solution

Update the WordPress ThumbPress plugin to the latest available version (at least 6.5).


OpenCVE Recommended Actions

  • Update the ThumbPress plugin to version 6.5 or later, which contains the authorization fix.
  • If an immediate update is not possible, disable or uninstall the ThumbPress plugin to prevent unauthenticated use of its features.
  • Apply server‑side access controls (e.g., http auth or IP restrictions) on the plugin’s endpoints to mitigate potential exploitation until a patch is applied.

Generated by OpenCVE AI on August 18, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Codexpert
Codexpert thumbpress
Wordpress
Wordpress wordpress
Vendors & Products Codexpert
Codexpert thumbpress
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Title WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Codexpert Thumbpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:12:43.305Z

Reserved: 2026-03-12T11:12:38.876Z

Link: CVE-2026-32549

cve-icon Vulnrichment

Updated: 2026-08-18T15:01:08.949Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:53.487

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-32549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:00:04Z

Weaknesses