Executive brief
Thrive Apprentice, a WordPress plugin used to create and manage online courses and memberships, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to inject malicious code into the website. If exploited, an attacker could gain full control over the site, steal sensitive customer data, or disrupt business operations.
Technical details
A PHP Object Injection vulnerability exists in the Thrive Apprentice plugin for WordPress due to the improper deserialization of user-supplied input. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to arbitrary code execution, SQL injection, or full system compromise. The vulnerability is addressed in version 10.8.10.2.
Affected products
- Thrive Themes Thrive Apprentice < 10.8.10.2
Timeline
- 2026-04-18: other: Reported by researcher dutafi
- 2026-06-04: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date