Description
WordPress Plugin Custom Content Type Manager contains a backdoor. Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Custom Content Type Manager versions 0.9.8.7 and 0.9.8.8 are the only one affected.
Remediation
Update to plugin version 0.9.8.9 or latest
References
https://blog.sucuri.net/2016/03/when-wordpress-plugin-goes-bad.html
https://wordpress.org/support/topic/version-0989-is-safe
https://wordpress.org/support/topic/vulnerability-on-auto-updatephp
https://wordpress.org/plugins/custom-content-type-manager/changelog/
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1167)
Jenkins Improper Input Validation Vulnerability (CVE-2013-0331)
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-14251)
Jenkins Insufficient Session Expiration Vulnerability (CVE-2019-1003004)