WordPress security by component
Thrive Leads
Plugin description
Thrive Leads is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
thrive-leadsLatest vulnerability
CVE-2026-65435: Thrive Leads exposes an unauthenticated privileged operation
Thrive Leads through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-65435
Thrive Leads exposes an unauthenticated privileged operation
Thrive Leads through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
|
10.9.2.1 |
CVE6.5
NVDPending
|