Description
WordPress Plugin WatchTowerHQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download/delete arbitrary files. WordPress Plugin WatchTowerHQ version 3.6.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.6.16 or latest
References
Related Vulnerabilities
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.31)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.17.29)
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
Oracle HTTP Server CVE-2018-2561 Vulnerability (CVE-2018-2561)
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2025-1948)