Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

2 vulnerability records

HighCVE-2026-49107

Thrive Apprentice < 10.8.10.2 - Unauthenticated PHP Object Injection

Thrive Apprentice: Currently marked unpatched

Affected versions: [*, 10.8.10.2)

Vulnerability type: CWE-502 Deserialization of Untrusted Data

Affected software, patched versions and attribution

The Thrive Apprentice plugin for WordPress is vulnerable to PHP Object Injection in versions up to 10.8.10.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Thrive Apprentice

Affected versions: [*, 10.8.10.2)

Patched versions: 10.8.10.2

Researcher credit: dutafi

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 4, 2026
CVSS
8.1
MediumCVE-2021-24219

Multiple Thrive Themes and Plugins (Various Versions) - Arbitrary Options Update

Thrive Optimize: Currently marked unpatchedThrive Dashboard: Currently marked unpatchedThrive Leads: Currently marked unpatchedThrive Clever Widgets: Currently marked unpatchedThrive Themes Builder: Currently marked unpatchedThrive Ultimatum: Currently marked unpatchedIgnition: Currently marked unpatchedStoried: Currently marked unpatchedThrive Apprentice: Currently marked unpatchedLuxe: Currently marked unpatchedThrive Comments: Currently marked unpatchedVoice: Currently marked unpatchedThrive Visual Editor: Currently marked unpatchedThrive Ovation: Currently marked unpatchedSquared: Currently marked unpatchedPerformag: Currently marked unpatchedMinus: Currently marked unpatchedThrive Quiz Builder: Currently marked unpatchedPressive: Currently marked unpatchedRise: Currently marked unpatchedFocusBlog: Currently marked unpatchedThrive Headline Optimizer: Currently marked unpatched

Affected versions: [*, 1.4.13.3); [*, 2.3.9.3); [*, 2.3.9.4); [*, 1.57.1); [*, 2.2.4); [*, 2.3.9.4); [*, 2.0.0); [*, 2.0.0)

Vulnerability type: CWE-284 Improper Access Control

Affected software, patched versions and attribution

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0, Thrive Themes Builder WordPress theme before 2.2.4 register a REST API endpoint associated with Zapier functionality. While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled. Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.

Thrive Optimize

Affected versions: [*, 1.4.13.3)

Patched versions: 1.4.13.3

Thrive Dashboard

Affected versions: [*, 2.3.9.3)

Patched versions: 2.3.9.3

Thrive Leads

Affected versions: [*, 2.3.9.4)

Patched versions: 2.3.9.4

Thrive Clever Widgets

Affected versions: [*, 1.57.1)

Patched versions: 1.57.1

Thrive Themes Builder

Affected versions: [*, 2.2.4)

Patched versions: 2.2.4

Thrive Ultimatum

Affected versions: [*, 2.3.9.4)

Patched versions: 2.3.9.4

Ignition

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Storied

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Thrive Apprentice

Affected versions: [*, 2.3.9.4)

Patched versions: 2.3.9.4

Luxe

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Thrive Comments

Affected versions: [*, 1.4.15.3)

Patched versions: 1.4.15.3

Voice

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Thrive Visual Editor

Affected versions: [*, 2.6.7.4)

Patched versions: 2.6.7.4

Thrive Ovation

Affected versions: [*, 2.4.5)

Patched versions: 2.4.5

Squared

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Performag

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Minus

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Thrive Quiz Builder

Affected versions: [*, 2.3.9.4)

Patched versions: 2.3.9.4

Pressive

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Rise

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

FocusBlog

Affected versions: [*, 2.0.0)

Patched versions: 2.0.0

Thrive Headline Optimizer

Affected versions: [*, 1.3.7.3)

Patched versions: 1.3.7.3

Researcher credit: Wordfence

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 23, 2021
CVSS
5.3

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.