Description
WordPress Plugin Thrive Apprentice is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Apprentice version 2.3.9.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.9.4 or latest
References
Related Vulnerabilities
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.7)
Dotclear Other Vulnerability (CVE-2006-3938)
WordPress Plugin Revive Old Post-Auto Post to Social Media 'cat' Parameter SQL Injection (3.2.5)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2018-14478)
WordPress Plugin PDF & Print by BestWebSoft Cross-Site Scripting (1.9.3)