Description
WordPress Plugin Thrive Apprentice is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Apprentice version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2356)
PrestaShop Files or Directories Accessible to External Parties Vulnerability (CVE-2020-5250)
WordPress Plugin Ajax Contact Form Cross-Site Scripting (1.0)
WordPress Plugin FormCraft-Contact Form Builder Cross-Site Request Forgery (1.2.1)