{"id":"CVE-2026-7622","published":"2026-09-22T08:16:40.387","lastModified":"2026-09-22T08:16:40.387","description":"The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the wp_ajax_pl-plugin-deactivation AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the ThumbPress plugin on the affected site by sending a crafted POST request to admin-ajax.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/tags/5.8.37/vendor/pluggable/marketing/src/Deactivator.php#L175","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/tags/5.8.37/vendor/pluggable/marketing/src/Deactivator.php#L58","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/trunk/vendor/pluggable/marketing/src/Deactivator.php#L175","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/image-sizes/trunk/vendor/pluggable/marketing/src/Deactivator.php#L58","tags":[]},{"url":"https://plugins.trac.wordpress.org/changeset/3560270","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2f998fd-eb15-442d-8034-af820601fe4a?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}