What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17.
Explanation of Vulnerability in Simple Terms
Thrive Automator versions up to 1.17 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of a logged-in user. The vulnerability requires the user to visit a malicious page while authenticated. An attacker can modify site settings or trigger automation workflows without the user's knowledge.
What an attacker can do
Perform actions on the site (modify settings, trigger workflows) on behalf of a logged-in user.
Potential impact on your site
Attackers can alter automation workflows or site configuration if they trick an admin into visiting a malicious link.
Conditions required to exploit
User must be logged in and visit an attacker-controlled page or link.
Key dates
External resources
Related vulnerabilities