ThumbPress – Stop Generating Unnecessary Thumbnails, CVE-2026-7622
- CVE, Research URL
- Published on
- Sep 22, 2026
- Research Description
- The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the ThumbPress plugin on the affected site by sending a crafted POST request to admin-ajax.
- Affected versions
-
max 6.2.2.
- Status
-
vulnerable