CVE-2026-4128: Tplugins TP Restore Categories And Taxonomies
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can()) to verify the user has sufficient permissions. While it does verify a nonce via check_ajax_referer(), this nonce is generated for all authenticated users via the admin_enqueue_scripts hook and exposed on any wp-admin page (including profile.php, which subscribers can access). This makes it possible for authenticated attackers, with Subscriber-level access and above, to permanently delete taxonomy term records from the plugin's trash/backup tables by sending a crafted AJAX request with a valid nonce and an arbitrary term_id.
Affected products
- Tplugins TP Restore Categories And Taxonomies: up to and including 1.0.1
Published 2026-04-22. Last modified 2026-06-17.