Missing Authorization Vulnerability in TP Restore Categories And Taxonomies Plugin for WordPress
CVE-2026-4128
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 April 2026
What is CVE-2026-4128?
The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to a missing authorization issue that arises when the delete_term() function processes the 'tpmcattt_delete_term' AJAX action. This function lacks a capability check to ensure users have the necessary permissions, despite validating a nonce using check_ajax_referer(). The nonce can be accessed by all authenticated users, including those with Subscriber-level access. As a result, an authenticated attacker can craft an AJAX request allowing them to permanently delete taxonomy term records from the plugin's trash and backup tables.
Affected Version(s)
TP Restore Categories And Taxonomies 0 <= 1.0.1