Cross-Site Request Forgery Vulnerability in ThimPress Thim Core Plugin
CVE-2025-53344

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
5 January 2026

What is CVE-2025-53344?

The Thim Press Thim Core plugin is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, allowing attackers to perform unauthorized actions on behalf of authenticated users. This occurs due to inadequate security measures within the plugin's request handling, affecting versions from n/a through 2.3.3. It is essential for users of Thim Core to implement appropriate security practices to mitigate the risks posed by this vulnerability.

Affected Version(s)

Thim Core <= 2.3.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal | Patchstack Threat Intelligence
.