Description
WordPress Plugin Thrive Leads is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Leads version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
MySQL CVE-2021-2172 Vulnerability (CVE-2021-2172)
MySQL CVE-2016-0502 Vulnerability (CVE-2016-0502)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.3.13.727)
MySQL CVE-2024-20971 Vulnerability (CVE-2024-20971)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.6.0)