Description
WordPress Plugin Thrive Clever Widgets is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add arbitrary data to a predefined option in the wp_options table. WordPress Plugin Thrive Clever Widgets version 1.56 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.56.1 or latest
References
Related Vulnerabilities
WordPress Plugin XCloner-Backup and Restore Multiple Vulnerabilities (3.1.2)
MediaWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-1055)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874)
WordPress Plugin Really Simple Share Cross-Site Request Forgery (2.9.9)