ThumbPress
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32549 | Hig | 0.42 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | ||
| CVE-2026-13432 | Med | 0.00 | 5.4 | 0.00 | Jul 20, 2026 | The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling… | ||
| CVE-2026-57720 | Med | 0.00 | 4.3 | 0.00 | Jul 1, 2026 | Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2. |
- risk 0.42cvss 7.5epss 0.00
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
- risk 0.00cvss 5.4epss 0.00
The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling…
- risk 0.00cvss 4.3epss 0.00
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.