Description
WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete the campaign cache. WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin version 1.2.49.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.50.0 or latest
References
https://wpscan.com/vulnerability/b9154128-2a30-450e-adc1-4c946cf9784f
https://plugins.svn.wordpress.org/mailoptin/trunk/changelog.txt
Related Vulnerabilities
WordPress Plugin Count per Day 'month' Parameter SQL Injection (2.17)
WordPress Plugin WooCommerce PayU India (PayUmoney-PayUbiz) Parameter Tampering (2.1.1)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.19)
WordPress Plugin IgniteUp-Coming Soon and Maintenance Mode Multiple Vulnerabilities (3.4)