Description
WordPress Plugin Image Source Control is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary post meta fields. WordPress Plugin Image Source Control version 2.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:3550BA54-7786-4AD9-AEB1-1C0750F189D0
https://plugins.svn.wordpress.org/image-source-control-isc/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform Multiple Vulnerabilities (2.21.2)
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2079)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1200)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-35525)