Description
WordPress Plugin Stylish Price List is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently upload arbitrary images. WordPress Plugin Stylish Price List version 6.8.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.9.0 or latest
References
Related Vulnerabilities
WordPress Plugin Client Dash Cross-Site Scripting (2.1.4)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2660)
Moodle Improper Privilege Management Vulnerability (CVE-2019-3849)
WordPress Plugin Abandoned Cart Lite for WooCommerce Cross-Site Scripting (5.1.3)
WordPress Plugin Plainview Activity Monitor Remote Command Execution (20161228)