Executive brief
ThumbPress is a popular WordPress plugin for managing and displaying image galleries on websites. An unauthenticated vulnerability in versions before 6.5 allows attackers to bypass access controls and view or manipulate content they should not have permission to access, potentially exposing sensitive data or compromising site functionality without requiring any credentials or authentication.
Technical details
This is a broken access control vulnerability (OWASP A1) in ThumbPress WordPress plugin versions prior to 6.5. The vulnerability allows unauthenticated attackers to bypass authorization checks and access pages or perform actions they should not be permitted to execute. The attack requires no authentication or special privileges and is network-reachable, making it widely exploitable. An attacker can view other users' data or perform unauthorized actions. The vulnerability has been patched in version 6.5 and later; administrators should update immediately.
Affected products
- ThumbPress ThumbPress < 6.5
Timeline
- 2026-08-18: disclosed
- 2026-08-17: advisory: Patchstack database entry published