Description
WordPress Plugin Convert Plus is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create new accounts. WordPress Plugin Convert Plus version 3.4.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.5 or latest
References
Related Vulnerabilities
Python Improper Input Validation Vulnerability (CVE-2023-27043)
Joomla! Core 3.9.x Cross-Site Request Forgery (3.9.0 - 3.9.19)
PHP Improper Input Validation Vulnerability (CVE-2011-1470)
WordPress Plugin FD Feedburner Cross-Site Request Forgery (1.42)
WordPress Plugin LearnDash LMS Arbitrary File Upload (2.5.3)