Description
WordPress Plugin Apocalypse Meow is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass Bcrypt authentication mechanism. WordPress Plugin Apocalypse Meow versions starting from 21.1.3 and up to, and including 21.2.7 are vulnerable.
Remediation
Update to plugin version 21.2.8 or latest
References
https://twitter.com/Sc00bzT/status/937124418500866048
https://plugins.svn.wordpress.org/apocalypse-meow/trunk/readme.txt
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2021-21639)
WordPress Plugin WordPress Poll Multiple Unspecified Vulnerabilities (35.0)
WordPress Plugin Header Footer Code Manager Cross-Site Scripting (1.1.16)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-3379)
Jenkins Improper Input Validation Vulnerability (CVE-2016-0789)