SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13432

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The ThumbPress WordPress plugin prior to version 6.2.2 is vulnerable due to a lack of capability checks on specific AJAX actions, enabling authenticated users with subscriber-level access or higher to deactivate the plugin. This can lead to disruptions in the site's image-handling functionality, potentially affecting user experience and site performance. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13432
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.