Unauthorized Access Vulnerability in ThumbPress Plugin for WordPress
CVE-2026-7622
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-7622?
The ThumbPress plugin on WordPress has a vulnerability that enables authenticated attackers with Subscriber-level access or higher to deactivate the plugin via a crafted POST request. This security flaw arises from the absence of capability checks and nonce verification within the send_deactivation_survey() function, linked to the wp_ajax_pl-plugin-deactivation action. Without proper validation mechanisms, an attacker could manipulate the site, potentially leading to further security breaches.
Affected Version(s)
ThumbPress β Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More 0 <= 6.2.1