Description
WordPress Plugin Async JavaScript is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's settings. WordPress Plugin Async JavaScript version 2.19.07.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.20.02.27 or latest
References
Related Vulnerabilities
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Request Forgery (4.8.4)
WordPress Plugin Global Content Blocks 'gcb_export.php' SQL Injection (1.2)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.93)
WordPress Plugin WP-Filebase Download Manager 'base' Parameter SQL Injection (0.2.9)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.1)