Description
WordPress Plugin Thrive Ovation is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Ovation version 2.4.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.4.5 or latest
References
Related Vulnerabilities
Contao Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10642)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-8098)
Moodle Credentials Management Errors Vulnerability (CVE-2012-0794)
MySQL Cleartext Transmission of Sensitive Information Vulnerability (CVE-2017-3305)
MySQL Use of Externally-Controlled Format String Vulnerability (CVE-2006-3469)