Thrive Themes · Thrive Apprentice · CVE-2026-49107
**Name of the Vulnerable Software and Affected Versions**
Thrive Apprentice versions prior to 10.8.10.2
**Description**
An unauthenticated PHP Object Injection exists due to the deserialization of untrusted input. This allows an attacker to inject a PHP Object. While no POP chain (a sequence of gadgets used to achieve code execution) is present in the software itself, the presence of a POP chain via another installed plugin or theme could enable the deletion of arbitrary files, retrieval of sensitive data, or remote code execution.
**Recommendations**
Update to version 10.8.10.2 or later.