Description
WordPress Plugin Thrive Ultimatum is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Ultimatum version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
MySQL CVE-2024-21102 Vulnerability (CVE-2024-21102)
WordPress Plugin Archivist-Custom Archive Templates Multiple Vulnerabilities (1.7.4)
Oracle JRE CVE-2014-0456 Vulnerability (CVE-2014-0456)
WordPress Plugin Remove WP Update Nags Security Bypass (1.3.0)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-20612)