Junglewise Threat Intelligence

CVE-2026-65435: Thrive Themes Thrive Leads broken access control

CVE-2026-65435 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Vendors: Thrive Themes.

Executive brief

Thrive Leads, a popular WordPress plugin used for building mailing lists and conversion forms, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could exploit this to modify settings or disrupt the plugin's functionality without needing a password. This could lead to unauthorized changes to lead generation forms or impact the site's ability to collect customer data.

Technical details

The Thrive Leads plugin for WordPress suffers from a broken access control vulnerability (CWE-862) due to missing authorization checks in certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 6.5, indicating a moderate impact on integrity and availability. The issue is resolved in version 10.9.2.1.

Affected products

  • Thrive Themes Thrive Leads <= 10.9.2

Timeline

  • 2026-06-18: disclosed: Reported by Dave Jong (Patchstack)
  • 2026-07-27: advisory: NVD and Patchstack advisory published
  • 2026-07-27: patched: Patch released in version 10.9.2.1

References