Description
WordPress Plugin Stylish Price List is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently upload arbitrary images. WordPress Plugin Stylish Price List version 6.8.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.9.0 or latest
References
Related Vulnerabilities
MyBB Insertion of Sensitive Information into Log File Vulnerability (CVE-2015-8977)
Apache Tomcat Improper Access Control Vulnerability (CVE-2014-7810)
Oracle JRE CVE-2014-2402 Vulnerability (CVE-2014-2402)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4301)
WordPress Plugin Slideshow Gallery LITE Multiple Cross-Site Scripting Vulnerabilities (1.6.5)