Impact
The vulnerability is a missing authorization flaw in the Codexpert Inc ThumbPress WordPress plugin, which allows an authenticated user to alter the plugin’s configuration settings. The weakness, classified as CWE-862, can enable changes that affect image handling, sizes, and other visual aspects of the site, potentially disrupting user experience or enabling further compromise.
Affected Systems
The affected product is Codexpert Inc ThumbPress for WordPress, any version up toPress site that installed and activated the plugin is at no update beyond 6.3.2 has been applied.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely at this time, and the vulnerability is not listed in CISA KEV. Based on the description, the attack vector is through the WordPress web interface, requiring an authenticated session with sufficient privileges to access the ThumbPress settings. An attacker who gains such access can modify configuration values, potentially altering site appearance or indirectly aiding further attacks.
OpenCVE Enrichment