WordPress is prone to same origin method execution (SOME) vulnerability. The impact of a SOME attack is similar to the impact of cross-site scripting, though there are some important and distinguishing exploitation restrictions. An attacker may leverage this issue to hijack dangerous web functionality and even exfiltrate sensitive user data. WordPress versions 3.8.x ranging from 3.8 and up to (and including) 3.8.13 are vulnerable.
Update to WordPress version 3.8.14 or latest
WordPress Plugin Profile Builder-User Profile & User Registration Forms Security Bypass (3.1.0)
WordPress Plugin Spectra-WordPress Gutenberg Blocks Cross-Site Scripting (1.14.11)
WordPress Plugin Catchers Helpdesk and Ticket system for Support Cross-Site Scripting (2.6.7)
WordPress Plugin WP-Live Chat by 3CX Arbitrary File Upload (8.0.31)
WordPress Plugin WP FuneralPress Multiple Cross-Site Scripting Vulnerabilities (1.1.6)