VYPR

ThumbPress

by WordPress

CVEs (3)

  • CVE-2026-32549HigAug 18, 2026
    risk 0.42cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

  • CVE-2026-13432MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling…

  • CVE-2026-57720MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.