Description
WordPress Plugin MailUp newsletter sign-up form is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings via 'formData=save' requests. WordPress Plugin MailUp newsletter sign-up form version 1.3.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.3 or latest
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4018)
WordPress Plugin Uji Countdown Cross-Site Scripting (2.2)
MediaWiki Other Vulnerability (CVE-2005-3167)
WordPress Plugin BulletProof Security Cross-Site Scripting (.50.9)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7537)