Description
WordPress Plugin Thrive Ultimatum is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Ultimatum version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
WordPress Plugin Post Views Count (Support caching plugins!) Cross-Site Scripting (3.0.2)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Multiple Vulnerabilities (5.2.4)
WordPress Plugin WPS Hide Login Multiple Security Bypass Vulnerabilities (1.5.2.2)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.2)
WordPress Plugin Easy Testimonials Cross-Site Scripting (3.5.2)