Description
WordPress Plugin Drop Shadow Boxes is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently perform a variety of the plugin's actions or even take over a website. WordPress Plugin Drop Shadow Boxes version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.2 or latest
References
https://github.com/Freemius/wordpress-sdk/commit/50a7ca3d921d59e1d2b39bb6ab3c6c7efde494b8
https://plugins.svn.wordpress.org/drop-shadow-boxes/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin NEX-Forms-Ultimate Form builder Multiple SQL Injection Vulnerabilities (4.0)
WordPress Plugin Image Slider Unspecified Vulnerability (1.1.119)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4297)
Ruby on Rails Improper Authentication Vulnerability (CVE-2012-3424)
Cherokee Improper Authentication Vulnerability (CVE-2014-4668)