Thrive Themes Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Thrive Themes products.
Products
- Thrive Theme Builder3 vulnerabilities
- FocusBlog by Thrive Themes2 vulnerabilities
- Ignition by Thrive Themes2 vulnerabilities
- Luxe by Thrive Themes2 vulnerabilities
- Minus by Thrive Themes2 vulnerabilities
- Performag by Thrive Themes2 vulnerabilities
- Pressive by Thrive Themes2 vulnerabilities
- Rise by Thrive Themes2 vulnerabilities
- Squared by Thrive Themes2 vulnerabilities
- Storied by Thrive Themes2 vulnerabilities
- Thrive Apprentice2 vulnerabilities
- Voice2 vulnerabilities
- Thrive Automator1 vulnerability
- Thrive Clever Widgets1 vulnerability
- Thrive Comments1 vulnerability
- Thrive Dashboard1 vulnerability
- Thrive Headline Optimizer1 vulnerability
- Thrive Leads1 vulnerability
- Thrive Optimize1 vulnerability
- Thrive Ovation1 vulnerability
- Thrive Quiz Builder1 vulnerability
- Thrive Themes Builder1 vulnerability
- Thrive Ultimatum1 vulnerability
- Thrive Visual Editor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-49107CRITICAL | WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnerabilityUnauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. CWE-502Jun 17, 2026 | CVSS9.8v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47783HIGH | WordPress Thrive Theme Builder theme < 3.24.0 - Multiple Authenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in Thrive Themes Thrive Theme Builder.This issue affects Thrive Theme Builder: from n/a before 3.24.0. CWE-862Jun 19, 2024 | CVSS8.3v3.1 | EPSS0.356% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47782HIGH | WordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0. CWE-269May 17, 2024 | CVSS8.8v3.1 | EPSS0.526% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51531MEDIUM | WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17. CWE-352Feb 29, 2024 | CVSS5.4v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47781HIGH | WordPress Thrive Theme Builder Theme < 3.24.2 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder < 3.24.2 versions. CWE-352Nov 22, 2023 | CVSS8.8v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24220CRITICAL | All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option DeletionThrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by… | CVSS9.1v3.1 | EPSS3.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24219MEDIUM | All Thrive Themes and Plugins - Unauthenticated Option UpdateThe Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin b… | CVSS5.3v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |