Description
WordPress Plugin WP Data Access is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently make unauthorized AJAX calls and access the debug logs. WordPress Plugin WP Data Access version 5.1.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.4 or latest
References
Related Vulnerabilities
WebLogic CVE-2018-2933 Vulnerability (CVE-2018-2933)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5498)
WordPress Plugin Forums 'url' Parameter Arbitrary File Disclosure (1.4.3)
WordPress Plugin Link Log-external link click monitor SQL Injection (2.0)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7853)