Description
WordPress Plugin Logo Slider and Showcase is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Logo Slider and Showcase version 1.3.36 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.37 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:8DFC86E4-56A0-4E30-9050-CF3F328FF993
https://plugins.svn.wordpress.org/wp-logo-showcase/trunk/README.txt
Related Vulnerabilities
WordPress Plugin WooCommerce Arbitrary File Deletion (3.4.5)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0796)
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-3850)
Claroline Other Vulnerability (CVE-2006-7048)
Magento Incorrect Authorization Vulnerability (CVE-2022-34256)