Description
WordPress Plugin Thrive Clever Widgets is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Clever Widgets version 1.56 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.56.1 or latest
References
Related Vulnerabilities
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000481)
WordPress Plugin W3 Total Cache Multiple Unspecified Vulnerabilities (0.9.5.1)
Drupal Core 8.8.x Remote Code Execution (8.8.0 - 8.8.7)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-0214)