← WordPress Vulnerabilities
WordPress security by component

Thrive Leads

Thrive Leads is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: thrive-leads

CVE-2026-65435: Thrive Leads exposes an unauthenticated privileged operation

Thrive Leads through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version10.9.2.1
Safe version
Jul 27, 2026 CVE-2026-65435
Thrive Leads exposes an unauthenticated privileged operation
Thrive Leads through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
10.9.2.1
CVE6.5
NVDPending