CVE-2021-24219

Public Exploit
All Thrive Themes and Plugins - Unauthenticated Option Update

Description

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0, Thrive Themes Builder WordPress theme before 2.2.4 register a REST API endpoint associated with Zapier functionality. While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled. Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.

Categories

5.3
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.18%
Third-Party Advisory wpscan.com Third-Party Advisory wordfence.com
Affected: Thrive Themes Thrive Optimize
Affected: Thrive Themes Thrive Comments
Affected: Thrive Themes Thrive Headline Optimizer
Affected: Thrive Themes Thrive Leads
Affected: Thrive Themes Thrive Ultimatum
Affected: Thrive Themes Thrive Quiz Builder
Affected: Thrive Themes Thrive Apprentice
Affected: Thrive Themes Thrive Visual Editor
Affected: Thrive Themes Thrive Dashboard
Affected: Thrive Themes Thrive Ovation
Affected: Thrive Themes Thrive Clever Widgets
Affected: Thrive Themes Rise by Thrive Themes
Affected: Thrive Themes Ignition by Thrive Themes
Affected: Thrive Themes Luxe by Thrive Themes
Affected: Thrive Themes FocusBlog by Thrive Themes
Affected: Thrive Themes Minus by Thrive Themes
Affected: Thrive Themes Squared by Thrive Themes
Affected: Thrive Themes Voice
Affected: Thrive Themes Performag by Thrive Themes
Affected: Thrive Themes Pressive by Thrive Themes
Affected: Thrive Themes Storied by Thrive Themes
Affected: Thrive Themes Thrive Themes Builder
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-24219?
CVE-2021-24219 has been scored as a medium severity vulnerability.
How to fix CVE-2021-24219?
To fix CVE-2021-24219, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2021-24219 being actively exploited in the wild?
It is possible that CVE-2021-24219 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-24219?
CVE-2021-24219 affects Thrive Themes Thrive Optimize, Thrive Themes Thrive Comments, Thrive Themes Thrive Headline Optimizer, Thrive Themes Thrive Leads, Thrive Themes Thrive Ultimatum, Thrive Themes Thrive Quiz Builder, Thrive Themes Thrive Apprentice, Thrive Themes Thrive Visual Editor, Thrive Themes Thrive Dashboard, Thrive Themes Thrive Ovation, Thrive Themes Thrive Clever Widgets, Thrive Themes Rise by Thrive Themes, Thrive Themes Ignition by Thrive Themes, Thrive Themes Luxe by Thrive Themes, Thrive Themes FocusBlog by Thrive Themes, Thrive Themes Minus by Thrive Themes, Thrive Themes Squared by Thrive Themes, Thrive Themes Voice, Thrive Themes Performag by Thrive Themes, Thrive Themes Pressive by Thrive Themes, Thrive Themes Storied by Thrive Themes, Thrive Themes Thrive Themes Builder.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.