Description
WordPress Plugin Bloom eMail Opt-In is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin Bloom eMail Opt-In version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
http://www.pritect.net/blog/elegant-themes-security-vulnerability
http://wptavern.com/critical-security-vulnerability-discovered-in-elegant-themes-products
http://us7.campaign-archive2.com/?u=9ae7aa91c578052b052b864d6&id=85b5d27651
Related Vulnerabilities
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2026-33110)
WebLogic CVE-2016-3445 Vulnerability (CVE-2016-3445)
Oracle JRE CVE-2012-0506 Vulnerability (CVE-2012-0506)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Arbitrary File Upload (1.0.2)
WordPress Plugin Side Menu-add fixed side buttons SQL Injection (3.1.3)