← WordPress Vulnerabilities
WordPress security by component

Thrive Product Manager

Thrive Product Manager is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.3.

Plugin slug: thrive-product-manager

CVE-2026-59535: Thrive Product Manager exposes an unauthenticated privileged operation

Thrive Product Manager through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version10.9.2.1
Safe version
Jul 27, 2026 CVE-2026-59535
Thrive Product Manager exposes an unauthenticated privileged operation
Thrive Product Manager through 10.9.2 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
10.9.2.1
CVE7.3
NVDPending