Description
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated broken access control flaw exists in the Thrive Leads Version plugin for WordPress, affecting all versions up to and including 10.9.2. This vulnerability allows an attacker with no prior authentication to access or manipulate protected plugin functionality that should be limited to authorized administrators. Because the flaw ignores or bypasses WordPress’s role‑based access checks, the attacker could read, modify, or delete lead data and potentially inject malicious content into the site. The breach compromises confidentiality, integrity, and user control over marketing data.

Affected Systems

The flaw affects sites running the Thrive Leads Version plugin by Thrive Themes Coupon originating from Thrive Themes. Specifically, any WordPress installation that has the plugin version 10.9.2 or older is vulnerable; the issue does not extend to newer releases beyond 10.9.2. Users of the affected plugin should verify the version number under the WordPress plugin dashboard and account for updates from the vendor.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of 0.00242 (< 1%) indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV list, suggesting a lower current exploitation window. Nonetheless, an attacker can potentially trigger the flaw simply by sending crafted HTTP requests to the plugin’s internal endpoints, meaning the exploit is straightforward when the plugin is exposed, especially on insecure or publicly accessible WordPress sites. Prompt remediation is advised to prevent unauthorized data access.

Generated by OpenCVE AI on August 3, 2026 at 17:31 UTC.

Remediation

Vendor Solution

Update the WordPress Thrive Leads Version Plugin to the latest available version (at least 10.9.2.1).


OpenCVE Recommended Actions

  • Upgrade the Thrive Leads Version plugin to the latest release (10.9.2.1 or newer).
  • Configure the web server or WordPress firewall to block unauthenticated requests to the plugin’s administrative URLs.
  • Review and tighten the plugin’s configuration and WordPress role permissions to ensure only administrators can access and modify lead data.

Generated by OpenCVE AI on August 3, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Thrive Themes Coupon
Thrive Themes Coupon thrive Leads Version
Wordpress
Wordpress wordpress
Vendors & Products Thrive Themes Coupon
Thrive Themes Coupon thrive Leads Version
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Title WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Thrive Themes Coupon Thrive Leads Version
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:59:07.324Z

Reserved: 2026-07-22T08:52:41.029Z

Link: CVE-2026-65435

cve-icon Vulnrichment

Updated: 2026-07-27T14:59:00.240Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:08.760

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-65435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses