Description
Vanilla 2.6.x before 2.6.4 allows remote code execution.
Remediation
References
Related Vulnerabilities
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10268)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7872)
WordPress Plugin Caret Country Access Limit Cross-Site Scripting (1.0.1)
WordPress Plugin WooCommerce PDF Invoices & Packing Slips Cross-Site Scripting (2.0.12)