Impact
The reported flaw is a missing authorization check in the Codexpert Inc ThumbPress WordPress plugin that permits unauthorized users to perform actions normally restricted by the plugin’s access control logic. This weakness is identified as CWE‑862 and could allow an attacker to alter protected configuration states or trigger privileged operations, thereby affecting the integrity of the site’s media handling or exposing further attack surface.
Affected Systems
Codexpert Inc ThumbPress for WordPress is vulnerable in all versions up to and including 6.3.2. Any WordPress installation with the plugin installed and activated at a version no higher than 6.3.2 is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. The EPSS value of < 1 % shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. It is inferred from the description that the attack does not require user authentication and would be carried out through the WordPress web interface, as the missing authorization condition implies that protected actions could be accessed by anyone who can reach the relevant plugin URLs.
OpenCVE Enrichment