CVE-2025-53345: WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerability
Published Jun 2, 2026
·Updated
Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core.
This issue affects Thim Core: from n/a through 2.3.3.
Affected Software
1 affected component
thimpress Thim Core<=2.3.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/thim-coreto a version that resolves this vulnerability.Fixed in 2.3.3
Event History
Jun 2, 2026
CVE Published
via MITRE·09:47 AM
Data Sourced
via MITRE·09:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Sep 20, 58388
Event
via NVD·07:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-53345?
The severity of CVE-2025-53345 is medium with a CVSS score of 6.5.
2
How can I fix CVE-2025-53345?
To fix CVE-2025-53345, update the Thim Core plugin to version 2.3.4 or later.
3
What type of vulnerability is CVE-2025-53345?
CVE-2025-53345 is an arbitrary code execution vulnerability caused by missing authorization.
4
Which versions of Thim Core are affected by CVE-2025-53345?
CVE-2025-53345 affects Thim Core plugin versions from n/a through 2.3.3.
5
What impact does CVE-2025-53345 have on WordPress sites?
CVE-2025-53345 can potentially allow unauthorized users to execute arbitrary code on affected WordPress sites.