Description
WordPress Plugin Convert Plus is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently register new accounts with Administrator privileges. WordPress Plugin Convert Plus version 3.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.3 or latest
References
Related Vulnerabilities
Oracle Application Server Credentials Management Errors Vulnerability (CVE-2002-2345)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0799)
MySQL CVE-2022-21324 Vulnerability (CVE-2022-21324 )
WordPress Plugin Easing Slider Multiple Cross-Site Scripting Vulnerabilities (2.2.0.6)