CyberRota Analysis
AI-GeneratedThe ThriveDesk plugin for WordPress is vulnerable to unauthorized cache deletion due to a lack of capability checks on the 'thrivedesk_clear_cache' AJAX action, affecting all versions up to 2.1.7. This vulnerability allows authenticated attackers with Subscriber-level access or higher to clear the plugin's cache, potentially disrupting service and affecting user experience. WordPress site administrators using this plugin should prioritize applying the latest updates to mitigate this risk.
Original NVD Description
The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the 'thrivedesk_clear_cache' AJAX action in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.