VYPR

ThumbPress

by WordPress

CVEs (2)

  • CVE-2026-13432Jul 20, 2026
    risk 0.00cvss epss 0.00

    The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling…

  • CVE-2026-57720Jul 1, 2026
    risk 0.00cvss epss 0.00

    Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.