S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 27, 2025

CVE-2021-24219 Scanner

CVE-2021-24219 Scanner - Unauthorized Option Update vulnerability in Thrive Themes and Plugins

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24219
5.3
CVSS

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0, Thrive Themes Builder WordPress theme before 2.2.4 register a REST API endpoint associated with Zapier functionality. While this endpoint was intended to require an API key in order to access, it was possible to access it by supplying an empty api_key parameter in vulnerable versions if Zapier was not enabled. Attackers could use this endpoint to add arbitrary data to a predefined option in the wp_options table.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Thrive Optimizeby Thrive Themes
AFFECTED< 1.4.13.3SAFE ✓≥ 1.4.13.3
Thrive Commentsby Thrive Themes
AFFECTED< 1.4.15.3SAFE ✓≥ 1.4.15.3
Thrive Headline Optimizerby Thrive Themes
AFFECTED< 1.3.7.3SAFE ✓≥ 1.3.7.3
Thrive Leadsby Thrive Themes
AFFECTED< 2.3.9.4SAFE ✓≥ 2.3.9.4
Updated Aug 21, 2026View on NVD →
Detail

Thrive Themes and Plugins are extensively used within the WordPress ecosystem to enhance website functionality and aesthetics. Small businesses, bloggers, marketers, and developers frequently employ these plugins and themes to optimize their WordPress sites. These plugins provide valuable features such as landing page creation, email list building, and quiz management, aiming to boost website performance and user engagement. They support diverse user bases, enabling customization and enhanced user interaction. With a focus on ease of use, these products are popular among non-technical users looking for professional site functionality without extensive coding knowledge. The wide adoption necessitates stringent security measures to safeguard websites from evolving cyber threats.

The unauthorized option update vulnerability allows attackers to exploit a REST API endpoint associated with Zapier functionality, which mistakenly provides access in specific conditions without requiring an API key. This vulnerability arises in instances where Zapier is not enabled, allowing malicious actors to bypass intended security checks. Attackers can potentially add arbitrary data to a predefined option in the wp_options table, impacting site integrity. This flaw heightens the risk of unauthorized changes to critical WordPress configuration data, leading to possible disruption of site operations. Misconfigured access controls inadvertently grant attackers more freedom to manipulate site options. This vulnerability emphasizes the need for constant monitoring and robust access control mechanisms.

Technical details of this vulnerability highlight a misconfiguration within the REST API, intended to require user authentication through an API key. However, erroneous code logic permits unauthenticated access by allowing empty api_key parameters. The affected endpoint, "/wp-json/td/v1/optin/subscription", exposes the site to malicious data insertion in its backend settings. Attackers are able to manipulate hooks and options stored in the wp_options table, leading to altered site configurations. The use of the POST method to access sensitive endpoints further elevates the potential impact. Effective exploitation depends on site setups lacking the necessary security checks for API requests. Proper assessment of this vulnerability's technical aspects can guide more secure API handling practices.

Exploitation of this vulnerability allows unauthorized users to make critical configuration changes within a WordPress installation without admin privileges. It poses a risk to data integrity, with altered settings potentially disrupting site functionality or introducing unwanted behavior. The systemic effects could extend to unauthorized data exposure, performance degradation, and undermined trust in site security. Given the extensive deployment of Thrive products, the oversight can leave numerous sites vulnerable to targeted attacks. Correction of security misconfigurations eliminates unauthorized access paths, safeguarding against malicious tampering and data theft. The vulnerability underscores the critical role of continuous security review and patch management for plugins.

REFERENCES

Solution Advice
  • Ensure all Thrive Themes and Plugins are updated to the latest versions.
  • Audit and secure REST API endpoints with proper authentication mechanisms.
  • Monitor and review site logs for unauthorized access attempts regularly.
  • Implement a robust patch management process to stay updated with security fixes.
  • Restrict public exposure of API endpoints only to trusted services.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.