{"id":"CVE-2026-7622","title":"The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1","summary":"The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"codexpert","product":"ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More","affected":["thumbpress_compress_images_manage_thumbnails_detect_image_issues_webp_avif_lazy_loading_hotlinking_more <= 6.2.1"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T11:17:25.413","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7622","references":[{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/tags/5.8.37/vendor/pluggable/marketing/src/Deactivator.php#L175","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/tags/5.8.37/vendor/pluggable/marketing/src/Deactivator.php#L58","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/trunk/vendor/pluggable/marketing/src/Deactivator.php#L175","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/trunk/vendor/pluggable/marketing/src/Deactivator.php#L58","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3560270","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2f998fd-eb15-442d-8034-af820601fe4a?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T10:08:11.831143Z"},"ingestedAt":"2026-09-22T08:00:27.686Z","slug":"CVE-2026-7622","body":"## Overview\n\nThe ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the ThumbPress plugin on the affected site by sending a crafted POST request to admin-ajax.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}