Description
WordPress Plugin AccessAlly is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin AccessAlly version 3.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.2 or latest
References
Related Vulnerabilities
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2021-32767)
Apache HTTP Server Other Vulnerability (CVE-2003-0987)
Advanced Custom Fields:Table Field Cross-Site Scripting (1.1.12)
Nginx CVE-2011-4963 Vulnerability (CVE-2011-4963)
VaultPress Man-in-The-Middle (MiTM) Remote Code Execution (1.8.6)