Description
WordPress Plugin WordPress Social Stream is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite admin options. WordPress Plugin WordPress Social Stream version 1.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.16 or latest
References
https://www.exploit-db.com/exploits/39946/
http://codecanyon.net/item/wordpress-social-stream/2201708?s_rank=15
Related Vulnerabilities
Java Unspesificed Vulnerability (CVE-2018-2940)
MongoDb Improper Encoding or Escaping of Output Vulnerability (CVE-2021-20333)
MySQL CVE-2021-35575 Vulnerability (CVE-2021-35575)
WordPress Plugin Widgets for WooCommerce Products on Elementor Security Bypass (1.0.5)
MongoDb Insertion of Sensitive Information into Log File Vulnerability (CVE-2026-8200)