CVE-2026-32549: WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Affected Software
1 affected component
wordpress/thumbpress<6.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ThumbPress pluginto a version that resolves this vulnerability.Fixed in 6.5
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this vulnerability?
Sites running ThumbPress versions earlier than 6.5 are affected. The issue is remotely reachable and does not require authentication or user interaction.
2
What does an attacker need to exploit it?
An attacker can exploit the broken access control without credentials. The provided severity vector indicates low attack complexity and potential high confidentiality impact, with no stated integrity or availability impact.
3
What is the available remediation?
Upgrade ThumbPress to version 6.5 or later. The provided data does not identify an alternative mitigation for sites that cannot patch immediately.