Impact
The ThriveDesk WordPress plugin exposes an AJAX action that clears its internal cache without performing a capability check. An authenticated user who has at least Subscriber‑level permissions can invoke this action, forcing the plugin to rebuild its cached data and producing a temporary loss of functionality. The flaw does not grant code execution or broader privilege escalation and is classified as an improper authorization problem (CWE‑862).
Affected Systems
All installations of the ThriveDesk WordPress plugin at version 2.1.7 or earlier are affected. The issue is present regardless of the site’s theme or other plugins, and no fix is documented in later releases according to the CVE data.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate severity range. With an EPSS score of less than 1 % the likelihood of exploitation in the wild is very low, and it is not listed in the CISA KEV catalog. An attacker only needs a valid WordPress account with Subscriber‑level privileges—common on many sites—to call the AJAX endpoint and delete the cache, causing brief service disruption for the plugin’s features. Overall, the risk remains low to moderate.
OpenCVE Enrichment