Unauthenticated PHP Object Injection in Thrive Apprentice Plugin by Thrive Themes
CVE-2026-49107

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-49107?

The Thrive Apprentice plugin versions prior to 10.8.10.2 are susceptible to unauthenticated PHP Object Injection. This vulnerability allows attackers to exploit the underlying PHP code through crafted input, leading to potential arbitrary code execution and compromise of sensitive data. As the plugin does not properly validate input, malicious actors can manipulate serialized objects, leading to severe security implications for websites using this outdated version of Thrive Apprentice.

Affected Version(s)

Thrive Apprentice < 10.8.10.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dutafi | Patchstack Bug Bounty Program
.