Thrive Themes (WordPress) Update
2592Warning Date
Severity Level
Warning Number
Target Sector
25 March, 2021
● Critical
2021-2671
All
Description:
Wordfence has released a security update to address several vulnerabilities in the following product:
- Thrive Themes
- All Legacy Themes, including Rise, Ignition, and others | Version < 2.0.0
- Thrive Optimize | Version < 1.4.13.3
- Thrive Comments | Version < 1.4.15.3
- Thrive Headline Optimizer | Version < 1.3.7.3
- Thrive Themes Builder | Version < 2.2.4
- Thrive Leads Version | < 2.3.9.4
- Thrive Ultimatum Version | < 2.3.9.4
- Thrive Quiz Builder Version | < 2.3.9.4
- Thrive Apprentice | Version < 2.3.9.4
- Thrive Architect | Version < 2.6.7.4
- Thrive Dashboard | Version < 2.3.9.3
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Unauthenticated Arbitrary File Upload and Option Deletion
Best practice and Recommendations:
The CERT team encourages users to review Wordfence security advisory and apply the necessary updates: