Thrive Leads Version <= 10.9.2 - Missing Authorization
medium
The Thrive Leads Version plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.9.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 10.9.2
- Fixed in:
- 10.9.2.1
- Disclosed:
- Jul 27, 2026
CVE-2026-65435 on NVD →
Multiple Thrive Themes and Plugins (Various Versions) - Arbitrary Options Update
medium
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive A...
- CVSS:
- 5.3
- Affected:
- up to 2.3.9.4
- Fixed in:
- 2.3.9.4
- Disclosed:
- Apr 23, 2021
CVE-2021-24219 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database