thrivethemes records
5 published records for vendor thrivethemes.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 60%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2021-24220Proof of concept | All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletionthrivethemes · focusblog · CWE-434 | Critical9.1 | — | 3.9% | Apr 12, 2021 |
35Monitor | CVE-2023-47782No exploit | WordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerabilitythrive themes · thrive theme builder · CWE-269 | High8.8 | — | 0.5% | May 17, 2024 |
35Monitor | CVE-2023-47781No exploit | WordPress Thrive Theme Builder Theme < 3.24.2 is vulnerable to Cross Site Request Forgery (CSRF)thrivethemes · thrive themes builder · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
35Monitor | CVE-2023-51531No exploit | WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF)thrivethemes · thrive automator · CWE-352 | High8.8 | — | 0.2% | Feb 29, 2024 |
22Monitor | CVE-2021-24219Proof of concept | All Thrive Themes and Plugins - Unauthenticated Option Updatethrivethemes · focusblog · CWE-284 | Medium5.3 | — | 2.1% | Apr 12, 2021 |
- CVE-2021-2422037Monitor
All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletion
CriticalCVSS 9.1Proof of conceptEPSS 4%thrivethemes · focusblogApr 12, 2021
- CVE-2023-4778235Monitor
WordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerability
HighCVSS 8.8No exploitEPSS 1%thrive themes · thrive theme builderMay 17, 2024
- CVE-2023-4778135Monitor
WordPress Thrive Theme Builder Theme < 3.24.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%thrivethemes · thrive themes builderNov 22, 2023
- CVE-2023-5153135Monitor
WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%thrivethemes · thrive automatorFeb 29, 2024
- CVE-2021-2421922Monitor
All Thrive Themes and Plugins - Unauthenticated Option Update
MediumCVSS 5.3Proof of conceptEPSS 2%thrivethemes · focusblogApr 12, 2021