Junglewise Threat Intelligence

CVE-2026-59544: Thrive Themes Thrive Quiz Builder PHP object injection

CVE-2026-59544 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Vendors: Thrive Themes.

Executive brief

Thrive Quiz Builder is a WordPress plugin used to create interactive quizzes for lead generation and customer engagement. A critical security flaw allows unauthenticated attackers to remotely inject malicious code into the website. If exploited, this could lead to a total site takeover, theft of customer data, or the complete deletion of website content.

Technical details

The Thrive Quiz Builder plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 10.9.3.0. This vulnerability arises from the insecure deserialization of user-supplied input (CWE-502), allowing an unauthenticated attacker to inject PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, an attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The attack can be executed over the network without any prior authentication or user interaction. The issue is resolved in version 10.9.3.1.

Affected products

  • Thrive Themes Thrive Quiz Builder <= 10.9.3.0

Timeline

  • 2026-06-27: other: Reported by researcher VanTastic
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References