CVE Feed

    Dashboard / CVE / CVE-2021-24219

    CVE-2021-24219

    The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0, Thrive Themes Builder WordPress theme before 2.2.4 register a REST API endpoint associated with Zapier functionality. While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled. Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.

    Published:Apr 12, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 12, 2021
    EPSS Score:0.00178
    CVSS Score:5.3

    Affected Products

    Vendor
    Thrivethemes
    Product
    Focusblog
    Vendor
    Thrivethemes
    Product
    Ignition
    Vendor
    Thrivethemes
    Product
    Luxe
    Vendor
    Thrivethemes
    Product
    Minus
    Vendor
    Thrivethemes
    Product
    Performag
    Vendor
    Thrivethemes
    Product
    Pressive
    Vendor
    Thrivethemes
    Product
    Rise
    Vendor
    Thrivethemes
    Product
    Squared
    Vendor
    Thrivethemes
    Product
    Storied
    Vendor
    Thrivethemes
    Product
    Thrive Apprentice
    Vendor
    Thrivethemes
    Product
    Thrive Clever Widgets
    Vendor
    Thrivethemes
    Product
    Thrive Comments
    Vendor
    Thrivethemes
    Product
    Thrive Dashboard
    Vendor
    Thrivethemes
    Product
    Thrive Headline Optimizer
    Vendor
    Thrivethemes
    Product
    Thrive Optimize
    Vendor
    Thrivethemes
    Product
    Thrive Ovation
    Vendor
    Thrivethemes
    Product
    Thrive Quiz Builder
    Vendor
    Thrivethemes
    Product
    Thrive Themes Builder
    Vendor
    Thrivethemes
    Product
    Thrive Visual Editor
    Vendor
    Thrivethemes
    Product
    Voice

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High