Description
WordPress Plugin Login as User or Customer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin Login as User or Customer version 1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8 or latest
References
Related Vulnerabilities
Joomla! Core 1.5.x Information Disclosure (1.5.0 - 1.5.12)
WordPress Plugin WP Mail Logging Cross-Site Scripting (1.11.1)
WordPress Plugin CM Download Manager Multiple Vulnerabilities (2.0.6)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Unspecified Vulnerability (4.8)
Oracle HTTP Server CVE-2018-2561 Vulnerability (CVE-2018-2561)