AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.483Z and has not been modified since then. This vulnerability affects Thrive Architect plugin version <= 10.9.3.1, allowing an attacker to inject malicious JavaScript code into the website, potentially leading to unauthorized actions or data breaches. Users of Thrive Architect plugin ver [truncated]
MEDIUMThrive Themes CouponCVE published 2026-07-27
CVE-2026-65435 is a MEDIUM severity vulnerability with a CVSS score of 6.5. It is an Unauthenticated Broken Access Control issue in Thrive Leads Version <= 10.9.2. The vulnerability allows attackers to bypass access controls, potentially leading to unauthorized actions. Users of Thrive Leads Version <= 10.9.2 should apply patches or mitigations to prevent exploitation. The CVSS vector is CVSS:3.1/AV:N/AC: [truncated]
CVE-2026-59535 is a HIGH-severity vulnerability in Thrive Product Manager plugin versions <= 10.9.2. It allows unauthenticated broken access control, with a CVSS score of 7.3. The vulnerability class is broken access control. Likely operational impact includes unauthorized access. Source confidence is high based on CVE and NVD data. Review context includes official CVE and NVD records.