theme

Thrive Theme Vulnerabilities

4 known security issues reported for the Thrive Theme WordPress theme. Most recent disclosed Nov 14, 2023.

3 high 1 medium

Running Thrive Theme on your site? Check whether your installed version is affected.

Scan your site free

Thrive Theme Builder < 3.24.2 - Cross-Site Request Forgery

high

The Thrive Theme Builder theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions prior to 3.24.2. This is due to missing or incorrect nonce validation on the affected function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can tric...

CVSS:
8.8
Affected:
up to 3.24.2
Fixed in:
3.24.2
Disclosed:
Nov 14, 2023

CVE-2023-47781 on NVD →

Thrive Theme Builder < 3.24.0 - Privilege Escalation

high

The Thrive Themes Builder theme for WordPress is vulnerable to privilege escalation in all versions prior to 3.24.0. This makes it possible for subscribers to elevate their privileges.

CVSS:
8.8
Affected:
up to 3.24.0
Fixed in:
3.24.0
Disclosed:
Nov 14, 2023

CVE-2023-47782 on NVD →

Thrive Theme Builder < 3.24.0 - Missing Authorization

high

The Thrive Theme Builder theme for WordPress is vulnerable to unauthorized use of functionality due to missing capability check in one of its functions in versions prior to 3.24.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke this function intended for higher-pri...

CVSS:
8.3
Affected:
up to 3.24.0
Fixed in:
3.24.0
Disclosed:
Nov 14, 2023

CVE-2023-47783 on NVD →

Multiple Thrive Themes and Plugins (Various Versions) - Arbitrary Options Update

medium

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive A...

CVSS:
5.3
Affected:
up to 2.2.4
Fixed in:
2.2.4
Disclosed:
Apr 23, 2021

CVE-2021-24219 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database