Description
WordPress Plugin Content Aware Sidebars-Unlimited Widget Areas is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently perform a variety of the plugin's actions or even take over a website. WordPress Plugin Content Aware Sidebars-Unlimited Widget Areas version 3.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.8.1 or latest
References
https://github.com/Freemius/wordpress-sdk/commit/50a7ca3d921d59e1d2b39bb6ab3c6c7efde494b8
https://plugins.svn.wordpress.org/content-aware-sidebars/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin CONTUS VBLOG-Video Blogging 'save.php' Arbitrary File Upload (1.0)
WordPress Plugin WP SVG Icons Multiple Unspecified Vulnerabilities (3.1.8.1)
Oracle Database Server CVE-2019-2582 Vulnerability (CVE-2019-2582)
Oracle HTTP Server Other Vulnerability (CVE-2020-35166)
WordPress Plugin Events Made Easy PHP Object Injection (2.0.52)