Description
WordPress Plugin Thrive Apprentice is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Apprentice version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin Bookly #1 WordPress Booking Plugin (Lite Version) Cross-Site Scripting (14.4)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2016-4978)
WordPress Plugin Editorial Calendar Multiple Vulnerabilities (2.6)
CrushFTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-32102)