Executive brief
Thim Core is a foundational WordPress plugin used by ThimPress themes to manage core functionalities and site settings. A security flaw allows logged-in users with low-level permissions to bypass authorization checks, potentially leading to the execution of unauthorized code on the server. This could result in a complete takeover of the website or the modification of sensitive site files.
Technical details
A Missing Authorization vulnerability (CWE-862) exists in the ThimPress Thim Core plugin for WordPress through version 2.3.3. The flaw allows an authenticated attacker, typically with Subscriber-level privileges, to bypass access controls due to insufficient validation of user permissions within certain plugin functions. According to the advisory, this lack of authorization can be leveraged to achieve arbitrary code execution (ACE). The attack is reachable over the network and does not require user interaction. As of the disclosure, no official patch has been released by the vendor.
Affected products
- ThimPress Thim Core <= 2.3.3
Timeline
- 2024-11-13: disclosed: Reported by Ananda Dhakal via Patchstack
- 2024-12-13: advisory: Initial Patchstack advisory published
- 2026-06-02: advisory: NVD publication date