Impact
The vulnerability is an unauthenticated cross‑site scripting flaw present in Thrive Architect plugin versions up to 10.9.3.1, allowing attackers to inject arbitrary HTML or JavaScript into the site. The weakness is classified as CWE‑79 and can lead to script execution in visitors’ browsers, potentially compromising user data and site integrity.
Affected Systems
Thrive Themes’ Thrive Architect plugin for WordPress, versions up to and including 10.9.3.1, affects any WordPress installation that has the plugin installed.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via unauthenticated submission of malicious scripts in editable content fields. Once triggered, the injected code can run in the context of any visitor’s browser, allowing data theft, defacement, or further site compromise.
OpenCVE Enrichment