Junglewise Threat Intelligence

CVE-2025-53346: ThimPress Thim Core missing authorization in access control

CVE-2025-53346 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Vendors: ThimPress.

Executive brief

Thim Core, a foundational WordPress plugin used by ThimPress themes, contains a security flaw in its access control mechanisms. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to access. While the impact is considered low, it could lead to unauthorized configuration changes or minor operational disruptions on affected websites.

Technical details

A missing authorization vulnerability (CWE-862) exists in the ThimPress Thim Core plugin for WordPress through version 2.3.3. The flaw stems from incorrectly configured access control security levels within the plugin's functional logic. An attacker authenticated with low-level privileges (Subscriber-level) can exploit this to execute functions or access settings that should be restricted to higher-privileged roles. The attack vector is network-based and requires no user interaction, though it does require valid low-level credentials. As of the advisory date, no official patch has been confirmed.

Affected products

  • ThimPress Thim Core <= 2.3.3

Timeline

  • 2024-11-13: other: Reported by researcher Ananda Dhakal
  • 2025-08-14: advisory: Early warning and publication by Patchstack
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats