Description
WordPress Plugin Logo Slider and Showcase is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Logo Slider and Showcase version 1.3.36 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.37 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:8DFC86E4-56A0-4E30-9050-CF3F328FF993
https://plugins.svn.wordpress.org/wp-logo-showcase/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Woody ad snippets-Insert Header Footer Code, AdSense Ads PHP Code Injection (1.3)
WordPress Plugin Cleeng-Sell your videos Cross-Site Scripting (2.3.2)
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-5542)
WordPress Improper Authentication Vulnerability (CVE-2008-1930)