Description
WordPress Plugin MailPress is prone to multiple vulnerabilities, including local file inclusion and security bypass vulnerabilities. Exploiting these issues could allow an attacker to obtain sensitive information that could aid in further attacks or to perform otherwise restricted actions and subsequently add or remove capabilities to WordPress roles. WordPress Plugin MailPress version 5.4.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Serendipity Other Vulnerability (CVE-2005-1452)
WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Vulnerabilities (2.0.77)
WordPress Plugin Download Plugin Arbitrary Directory Download (1.0.1)
WordPress Plugin WooCommerce Checkout Manager Cross-Site Request Forgery (4.3)
WordPress Plugin GN Publisher: Google News Compatible RSS Feeds Cross-Site Scripting (1.5.5)