CVE-2021-24219

High PUBLISHED

All Thrive Themes and Plugins - Unauthenticated Option Update

Thrive Themes · Thrive Optimize, Thrive Comments, Thrive Headline Optimizer, Thrive Leads, Thrive Ultimatum, Thrive Quiz Builder, Thrive Apprentice, Thrive Visual Editor, Thrive Dashboard, Thrive Ovation, Thrive Clever Widgets, Rise by Thrive Themes, Ignition by Thrive Themes, Luxe by Thrive Themes, FocusBlog by Thrive Themes, Minus by Thrive Themes, Squared by Thrive Themes, Voice, Performag by Thrive Themes, Pressive by Thrive Themes, Storied by Thrive Themes, Thrive Themes Builder

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
5.3 Medium EPSS 0.2%

At a Glance

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0, Thrive Themes Builder WordPress theme before 2.2.4 register a REST API endpoint associated with Zapier functionality. While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled. Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.

wordpress nuclei_scanner
CVE Published
Apr 12, 2021
Exploitation Reported
Mar 24, 2021
CVSS
5.3 Medium
EPSS
0.2%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Thrive Themes
Thrive Optimize

1.4.13.3 to < 1.4.13.3

Affected
Thrive Themes
Thrive Comments

1.4.15.3 to < 1.4.15.3

Affected
Thrive Themes
Thrive Headline Optimizer

1.3.7.3 to < 1.3.7.3

Affected
Thrive Themes
Thrive Leads

2.3.9.4 to < 2.3.9.4

Affected
Thrive Themes
Thrive Ultimatum

2.3.9.4 to < 2.3.9.4

Affected
Thrive Themes
Thrive Quiz Builder

2.3.9.4 to < 2.3.9.4

Affected
Thrive Themes
Thrive Apprentice

2.3.9.4 to < 2.3.9.4

Affected
Thrive Themes
Thrive Visual Editor

2.6.7.4 to < 2.6.7.4

Affected
Thrive Themes
Thrive Dashboard

2.3.9.3 to < 2.3.9.3

Affected
Thrive Themes
Thrive Ovation

2.4.5 to < 2.4.5

Affected
Thrive Themes
Thrive Clever Widgets

1.57.1 to < 1.57.1

Affected
Thrive Themes
Rise by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Ignition by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Luxe by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
FocusBlog by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Minus by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Squared by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Voice

2.0.0 to < 2.0.0

Affected
Thrive Themes
Performag by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Pressive by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Storied by Thrive Themes

2.0.0 to < 2.0.0

Affected
Thrive Themes
Thrive Themes Builder

2.2.4 to < 2.2.4

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.