Executive brief
Thrive Architect is a WordPress page builder plugin used to design and publish web pages. An unauthenticated attacker can inject malicious scripts into affected sites through user interaction (such as clicking a link or visiting a crafted page), potentially allowing theft of visitor data or account hijacking. The vulnerability affects versions 10.9.3.1 and earlier.
Technical details
This is an unauthenticated cross-site scripting (XSS) vulnerability in Thrive Architect WordPress plugin versions 10.9.3.1 and earlier. The vulnerability allows attackers to inject malicious JavaScript into the application, which is then executed in the browsers of site visitors. While the vulnerability is classified as unauthenticated (no login required to initiate the attack), successful exploitation requires user interaction—such as a victim clicking a malicious link or visiting a crafted page. An attacker can leverage this to steal session cookies, hijack user accounts, or harvest sensitive visitor data. The vulnerability was patched in version 10.9.3.2, and site administrators should update immediately.
Affected products
- Thrive Themes Thrive Architect <= 10.9.3.1
Timeline
- 2026-08-06: disclosed: Published on NVD
- 2026-08-04: patched: Patched in version 10.9.3.2