Description
WordPress Plugin Dropshix is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create spam pages. WordPress Plugin Dropshix version 4.0.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.14 or latest
References
Related Vulnerabilities
WordPress Plugin WordPress WP-Advanced-Search SQL Injection (3.3.5)
WordPress Plugin Juiz Social Post Sharer Multiple Cross-Site Scripting Vulnerabilities (1.3.3.7)
Oracle Database Server CVE-2013-3760 Vulnerability (CVE-2013-3760)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-20281)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-18033)