Description
WordPress Plugin Ultimate FAQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import CSV files and create new posts, or export all posts/FAQs. WordPress Plugin Ultimate FAQ version 1.8.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.25 or latest
References
Related Vulnerabilities
WordPress Plugin Velvet Blues Update URLs Unspecified Vulnerability (2.1)
Next.js CVE-2022-21721 Vulnerability (CVE-2022-21721)
WordPress Plugin Download Manager PHAR Deserialization (3.2.49)
PostgreSQL UNIX Symbolic Link (Symlink) Following Vulnerability (CVE-2026-6475)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-14630)