Description
WordPress Plugin Slick Popup:Contact Form 7 Popup is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Slick Popup:Contact Form 7 Popup version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.20)
SeoPanel Cross-site Scripting (XSS) Vulnerability (CVE-2020-35930)
MySQL CVE-2015-0391 Vulnerability (CVE-2015-0391)
WordPress Plugin Image Gallery with Slideshow 'upload-file.php' Arbitrary File Upload (1.5)
WordPress Plugin Duplicate Page Unspecified Vulnerability (3.5)