First published: Mon Apr 12 2021(Updated: )
Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken image optimization engine. By supplying a crafted request in combination with data inserted using the Option Update vulnerability, it was possible to use this endpoint to retrieve malicious code from a remote URL and overwrite an existing file on the site with it or create a new file.This includes executable PHP files that contain malicious code.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thrive Themes FocusBlog | <2.0.0 | |
Thrivethemes Ignition | <2.0.0 | |
Thrive Themes Luxe | <2.0.0 | |
Thrive Themes Minus | <2.0.0 | |
Thrive Themes Performag | <2.0.0 | |
Thrivethemes Pressive | <2.0.0 | |
Thrive Themes Rise | <2.0.0 | |
Thrivethemes Squared | <2.0.0 | |
Thrive Themes Storied | <2.0.0 | |
Thrive Themes Voice | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-24220 is critical, with a severity value of 9.1.
Thrive “Legacy” Rise, Luxe, Minus, Ignition, FocusBlog, Squared, Performag, Pressive, Storied, and Voice WordPress themes are affected by CVE-2021-24220.
To fix CVE-2021-24220, update the affected Thrive Themes WordPress themes to version 2.0.0 or higher.
The CWE ID of CVE-2021-24220 is 434.
You can find more information about CVE-2021-24220 on the following references: [Wordfence Blog](https://www.wordfence.com/blog/2021/03/recently-patched-vulnerability-in-thrive-themes-actively-exploited-in-the-wild) and [WPScan](https://wpscan.com/vulnerability/a2424354-2639-4f53-a24f-afc11f6c4cac).