Description
WordPress Plugin Custom Content Type Manager contains a backdoor. Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Custom Content Type Manager versions 0.9.8.7 and 0.9.8.8 are the only one affected.
Remediation
Update to plugin version 0.9.8.9 or latest
References
https://blog.sucuri.net/2016/03/when-wordpress-plugin-goes-bad.html
https://wordpress.org/support/topic/version-0989-is-safe
https://wordpress.org/support/topic/vulnerability-on-auto-updatephp
https://wordpress.org/plugins/custom-content-type-manager/changelog/
Related Vulnerabilities
WordPress Plugin Memphis Documents Library Cross-Site Request Forgery (3.9.20)
Ruby Other Vulnerability (CVE-2016-2337)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-28335)
WordPress Plugin Easy Org Chart Cross-Site Scripting (3.1)
Jboss EAP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-3878)