Description
WordPress Plugin Thrive Dashboard is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Dashboard version 2.3.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.3 or latest
References
Related Vulnerabilities
WordPress Plugin Awesome Studio Cross-Site Scripting (1.0.7)
WordPress Plugin Side Cart Woocommerce (Ajax) Cross-Site Request Forgery (2.0)
WordPress Plugin Page Builder by SiteOrigin Cross-Site Request Forgery (2.10.15)
WordPress Plugin Caldera Forms-More Than Contact Forms Information Disclosure (1.3.5.2)