CVE-2026-13432
Deferred Deferred - Pending Action

Authenticated Plugin Deactivation in ThumbPress WordPress Plugin

Vulnerability report for CVE-2026-13432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thumbpress thumbpress to 6.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ThumbPress WordPress plugin versions before 6.2.2. It involves insufficient capability checks in an AJAX action, allowing authenticated users with subscriber-level or higher access to deactivate the plugin. This disrupts the site's image-handling functionality.

Detection Guidance

Check the installed version of the ThumbPress plugin in your WordPress site. If it is below 6.2.2, the vulnerability is present. You can verify this via the WordPress admin panel under Plugins or by inspecting the plugin files on the server.

Impact Analysis

An attacker with subscriber-level access or higher could deactivate the ThumbPress plugin by sending a single AJAX request without a nonce. This would disable the site's image-handling features, potentially breaking image display and functionality.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA. It allows low-privileged users to deactivate a WordPress plugin, disrupting image-handling functionality. Compliance risks would arise only if the plugin's deactivation leads to unauthorized data exposure or processing failures, which is not specified in the provided context.

Mitigation Strategies

Update the ThumbPress plugin to version 6.2.2 or later immediately. If updating is not possible, consider temporarily disabling the plugin until an update is applied. Ensure all user accounts follow the principle of least privilege to minimize risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart