Description
WordPress Plugin 10Web AI Assistant-AI content writing assistant is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install and activate any plugin from the WordPress repo. WordPress Plugin 10Web AI Assistant-AI content writing assistant version 1.0.18 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.19 or latest
References
Related Vulnerabilities
WordPress Plugin Mini Mail Dashboard Widget 'abspath' Parameter Remote File Include (1.36)
WordPress Plugin SP Project & Document Manager Multiple Vulnerabilities (2.5.9.7)
WordPress Plugin GDPR Cookie Consent Security Bypass (1.8.2)
Cherokee Out-of-bounds Write Vulnerability (CVE-2019-20800)
WordPress Plugin Estatik Real Estate Arbitrary File Upload (2.2.5)