S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 23, 2025

CVE-2021-24220 Scanner

CVE-2021-24220 Scanner - Arbitrary File Upload vulnerability in Thrive Themes WordPress Themes

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24220
9.1
CVSS

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Rise by Thrive Themesby Thrive Themes
AFFECTED< 2.0.0SAFE ✓≥ 2.0.0
Luxe by Thrive Themesby Thrive Themes
AFFECTED< 2.0.0SAFE ✓≥ 2.0.0
Minus by Thrive Themesby Thrive Themes
AFFECTED< 2.0.0SAFE ✓≥ 2.0.0
Ignition by Thrive Themesby Thrive Themes
AFFECTED< 2.0.0SAFE ✓≥ 2.0.0
Updated Aug 21, 2026View on NVD →
Detail

Thrive Themes WordPress Themes are popular tools used by website developers and owners to create and manage themes on WordPress sites. These themes offer customizable features that enhance the appearance and functionality of websites, appealing to a wide range of users globally. Businesses and individuals both use these themes to build aesthetically pleasing and user-friendly sites. Thrive Themes are known for their flexibility, speed, and integration capabilities with various WordPress plugins. They have a substantial user base, especially among those seeking professional and fully functional WordPress themes. These themes often support advanced features such as drag-and-drop editing, customizable templates, and responsive design.

The Arbitrary File Upload vulnerability allows an attacker to upload malicious files onto a server running vulnerable software. This vulnerability arises due to inadequate validation or sanitization of file inputs in the affected Thrive Themes. Attackers can exploit this flaw by uploading files containing executable PHP code disguised as an image or another non-threatening file format. This can lead to unauthorized access or control over server resources by executing the malicious code. The vulnerability had been actively exploited, jeopardizing sites' security by potentially leading to a complete compromise. Keeping themes updated is crucial in mitigating this type of risk.

The vulnerability is technically rooted in the registration of a REST API endpoint used for image compression within the Thrive Themes, which can be manipulated to upload arbitrary files. Attackers can deploy crafted requests leveraging this endpoint to download malicious code from remote servers. This malicious code can overwrite existing files or create new ones, thereby executing unauthorized actions. The array of vulnerable themes includes Thrive 'Legacy' Rise, Luxe, Ignition, FocusBlog, and others before version 2.0.0. Exploiting this flaw requires no authenticated access, highlighting the severity of potential exploits against public-facing sites.

Exploiting this vulnerability could lead to several severe consequences. Successful exploitation can result in arbitrary code execution, allowing attackers to seize control over affected WordPress installations. This could facilitate data theft, site defacement, or use the site as a platform for further attacks. In worst-case scenarios, it can grant attackers significant access, equating to complete site takeover. Additionally, compromised sites might be leveraged for phishing or malware dissemination by the attackers. Users' confidential data could be at risk, inclusive of passwords or other sensitive information stored on these WordPress sites.

REFERENCES

Solution Advice
  • Update all affected Thrive Themes to version 2.0.0 or later to mitigate the vulnerability.
  • Regularly audit and monitor site activities to detect any unusual or suspicious uploads.
  • Implement stringent file upload restrictions, including mimetype verification and sanitized file naming conventions.
  • Utilize security plugins that offer additional layers of defense against unauthorized file uploads.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.