Description
WordPress Plugin BCS BatchLine Book Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/update arbitrary products. WordPress Plugin BCS BatchLine Book Importer version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:23B76562-D2AF-4753-BCE4-002921F3378E
https://plugins.svn.wordpress.org/bcs-bertline-book-importer/trunk/readme.txt
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1559)
Django Uncontrolled Resource Consumption Vulnerability (CVE-2019-14233)
WordPress Plugin BetterLinks-Shorten, Track and Manage any URL Cross-Site Scripting (1.2.5)
WordPress Plugin DM Albums 'album.php' Remote File Inclusion (1.9.2)