cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortp-restore-categories-and-taxonomies tp-restore-categories-and-taxonomies

Direction: ascending
Apr 23, 2026

TP Restore Categories And Taxonomies # CVE-2026-4128

CVE, Research URL

CVE-2026-4128

Date
Apr 22, 2026
Research Description
The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can()) to verify the user has sufficient permissions. While it does verify a nonce via check_ajax_referer(), this nonce is generated for all authenticated users via the admin_enqueue_scripts hook and exposed on any wp-admin page (including profile.php, which subscribers can access). This makes it possible for authenticated attackers, with Subscriber-level access and above, to permanently delete taxonomy term records from the plugin's trash/backup tables by sending a crafted AJAX request with a valid nonce and an arbitrary term_id.
Affected versions
max 1.0.1.
Status
vulnerable