Description
WordPress Plugin Logo Showcase with Slick Slider-Logo Carousel, Logo Slider & Logo Grid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change title, description, alt text, or URL of arbitrary uploaded media. WordPress Plugin Logo Showcase with Slick Slider-Logo Carousel, Logo Slider & Logo Grid version 1.2.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.5 or latest
References
Related Vulnerabilities
Perl Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-1999-1386)
MySQL CVE-2021-35626 Vulnerability (CVE-2021-35626)
WordPress Plugin WP Mailster Cross-Site Scripting (1.6.1)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35626)
WordPress Plugin Double Opt-In for Download Multiple Cross-Site Scripting Vulnerabilities (2.1.5)