Executive brief
Thrive Product Manager, a WordPress plugin used to manage and license Thrive Themes products, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could exploit this to bypass security restrictions, potentially leading to unauthorized changes or access to site data. This vulnerability is considered high priority as it does not require a password to exploit and could be used in automated attacks against WordPress websites.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Thrive Product Manager plugin for WordPress in versions up to and including 10.9.2. The flaw stems from a lack of proper authorization, authentication, or nonce checks in certain functions, allowing an unauthenticated remote attacker to execute privileged actions. Successful exploitation could impact the confidentiality, integrity, and availability of the affected site. The issue is resolved in version 10.9.2.1.
Affected products
- Thrive Themes Thrive Product Manager <= 10.9.2
Timeline
- 2026-05-26: disclosed: Reported by Austin Ginder
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: advisory: NVD published date
- 2026-07-27: patched: Version 10.9.2.1 confirmed as patched version