Description
PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.
Remediation
References
Related Vulnerabilities
WordPress Plugin Special Text Boxes Arbitrary File Upload (5.1.90)
WordPress Plugin WP Statistics SQL Injection (13.1.4)
WordPress Plugin HTML5 AV Manager for WordPress 'custom.php' Arbitrary File Upload (0.2.7)
WordPress Plugin SP Project & Document Manager Multiple Vulnerabilities (2.5.9.7)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Arbitrary File Upload (1.5.9)