Description
WordPress Plugin BCS BatchLine Book Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/update arbitrary products. WordPress Plugin BCS BatchLine Book Importer version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:23B76562-D2AF-4753-BCE4-002921F3378E
https://plugins.svn.wordpress.org/bcs-bertline-book-importer/trunk/readme.txt
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-1581)
WordPress Plugin Videox7 UGC 'listid' Parameter Cross-Site Scripting (2.5.3.2)
WordPress Plugin NextMove Lite-Thank You Page for WooCommerce Security Bypass (2.17.0)
WordPress Plugin 10Web Map Builder for Google Maps Security Bypass (1.0.63)