Executive brief
Thrive Leads, a popular WordPress plugin used for building mailing lists and conversion forms, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could exploit this to modify settings or disrupt the plugin's functionality without needing a password. This could lead to unauthorized changes to lead generation forms or impact the site's ability to collect customer data.
Technical details
The Thrive Leads plugin for WordPress suffers from a broken access control vulnerability (CWE-862) due to missing authorization checks in certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 6.5, indicating a moderate impact on integrity and availability. The issue is resolved in version 10.9.2.1.
Affected products
- Thrive Themes Thrive Leads <= 10.9.2
Timeline
- 2026-06-18: disclosed: Reported by Dave Jong (Patchstack)
- 2026-07-27: advisory: NVD and Patchstack advisory published
- 2026-07-27: patched: Patch released in version 10.9.2.1