Description
WordPress Plugin CiviCRM is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently read private data from the database. WordPress Plugin CiviCRM version 5.35.1 is vulnerable; prior versions are also affected.
Remediation
Update to plugin versions 5.36.1, 5.35.2, 5.33.5 ESR, or latest
References
Related Vulnerabilities
WordPress Plugin Solve Media CAPTCHA Cross-Site Request Forgery (1.1.0)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-3646)
WordPress 3.8.x Same Origin Method Execution (SOME) Vulnerability (3.8 - 3.8.13)
Jboss EAP Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-0853)