Impact
The vulnerability is a broken access control that permits unauthenticated users to access functionality normally restricted to authorized users within the Thrive Product Manager plugin. The specific actions that can be performed are not detailed, but the flaw potentially enables unauthorized manipulation of product‑related data. Based on the description, it is inferred that attackers could construct requests that affect the plugin’s content beyond normal usage.
Affected Systems
The issue affects WordPress installations running the Thrive Themes Coupon:Thrive Product Manager plugin with versions up to and including 10.9.2. Core WordPress and other plugins are not impacted.
Risk and Exploitability
The CVSS score of 7.3 indicates the flaw is high severity. According to the score, no authentication is required to exploit the vulnerability, meaning any site visitor could potentially trigger it. The EPSS score of < 1% points to a very low but nonzero probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers could construct requests that manipulate product data, potentially leading to unauthorized changes within the site.
OpenCVE Enrichment