Executive brief
ThumbPress, a WordPress plugin used for managing image sizes and thumbnails, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions (such as subscribers) to perform actions they should not be authorized to access. While the impact is limited, it could lead to unauthorized changes or minor service disruptions on the affected website.
Technical details
A missing authorization (CWE-862) vulnerability exists in the Codexpert Inc ThumbPress plugin for WordPress through version 6.3.2. The flaw stems from insufficient access control checks on certain functions, allowing an authenticated attacker with Subscriber-level privileges to execute actions intended for higher-privileged users. The attack vector is network-based and requires low privileges but no user interaction. The vulnerability has been addressed in version 6.3.3.
Affected products
- Codexpert Inc ThumbPress up to 6.3.2
Timeline
- 2025-07-20: disclosed: Reported by Denver Jackson
- 2026-07-01: advisory: Published by Patchstack and NVD
- 2026-07-01: patched: Fixed in version 6.3.3