Unauthorized Access Vulnerability in ThumbPress Plugin for WordPress
CVE-2026-7622

4.3MEDIUM

What is CVE-2026-7622?

The ThumbPress plugin on WordPress has a vulnerability that enables authenticated attackers with Subscriber-level access or higher to deactivate the plugin via a crafted POST request. This security flaw arises from the absence of capability checks and nonce verification within the send_deactivation_survey() function, linked to the wp_ajax_pl-plugin-deactivation action. Without proper validation mechanisms, an attacker could manipulate the site, potentially leading to further security breaches.

Affected Version(s)

ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More 0 <= 6.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Que Thanh Tuan
.