Description
WordPress Plugin Alphabetic Pagination is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugins's settings and allow registration with a default role of administrator. WordPress Plugin Alphabetic Pagination version 3.0.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:3D72B705-F1AB-4E20-AA2D-426B3151EEEA
https://plugins.svn.wordpress.org/alphabetic-pagination/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Video Player Multiple SQL Injection Vulnerabilities (1.5.16)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-39193)
osTicket Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-14749)
Moodle Incorrect Authorization Vulnerability (CVE-2024-48901)