Vulnerabilities and security researches forimage-sizes image-sizes
Direction: ascendingJul 03, 2026
ThumbPress – Stop Generating Unnecessary Thumbnails # CVE-2026-57720
- CVE, Research URL
- Date
- Jul 01, 2026
- Research Description
- Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
- Affected versions
-
max 6.3.3.
- Status
-
vulnerable
Jul 22, 2026
ThumbPress – Stop Generating Unnecessary Thumbnails # CVE-2026-13432
- CVE, Research URL
- Date
- Jul 20, 2026
- Research Description
- The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.
- Affected versions
-
max 6.2.2.
- Status
-
vulnerable
Aug 20, 2026
ThumbPress – Stop Generating Unnecessary Thumbnails # CVE-2026-32549
- CVE, Research URL
- Date
- Aug 18, 2026
- Research Description
- Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
- Affected versions
-
max 6.5.
- Status
-
vulnerable
Sep 23, 2026
ThumbPress – Stop Generating Unnecessary Thumbnails # CVE-2026-7622
- CVE, Research URL
- Date
- Sep 22, 2026
- Research Description
- The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the ThumbPress plugin on the affected site by sending a crafted POST request to admin-ajax.
- Affected versions
-
max 6.2.2.
- Status
-
vulnerable