Description
WordPress Plugin WordPress Social Stream is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite admin options. WordPress Plugin WordPress Social Stream version 1.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.16 or latest
References
https://www.exploit-db.com/exploits/39946/
http://codecanyon.net/item/wordpress-social-stream/2201708?s_rank=15
Related Vulnerabilities
WordPress Plugin WooCommerce Affiliate-Coupon Affiliates Cross-Site Scripting (4.11.0.1)
WordPress Plugin Sticky Popup Cross-Site Scripting (1.2)
WordPress Plugin Integration for Contact Form 7 and Constant Contact Cross-Site Scripting (1.0.8)
WordPress Plugin Featured Comments Cross-Site Request Forgery (1.2.1)
WordPress Plugin Admin Custom Login Cross-Site Scripting (2.5.3.1)