Description
WordPress Plugin Absolute Privacy is prone to a security bypass vulnerability. Attackers can exploit this vulnerability to bypass authentication mechanism and gain administrative access to an affected application, which may aid in further attacks. WordPress Plugin Absolute Privacy version 2.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.6 or latest
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop Multiple Cross-Site Scripting Vulnerabilities (2.4.1)
WordPress Plugin CSS & JavaScript Toolbox SQL Injection (9.2)
WordPress Plugin WP Video Lightbox Cross-Site Scripting (1.9.2)
WordPress Plugin Zero BS WordPress CRM Cross-Site Request Forgery (2.99.9)
WordPress 4.1.x Arbitrary File Deletion Vulnerability (4.1 - 4.1.23)