Description
WordPress Plugin Thrive Leads is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Leads version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin WP Mailster Cross-Site Scripting (1.6.1)
MySQL CVE-2019-2910 Vulnerability (CVE-2019-2910)
WordPress Plugin WP Statistics Cross-Site Scripting (12.6.3)
WordPress Plugin Kish Guest Posting 'uploadify.php' Arbitrary File Upload (1.2)
WordPress Plugin Essential Real Estate Cross-Site Scripting (1.7.0)