Description
WordPress Plugin WP Datepicker is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update arbitrary options. WordPress Plugin WP Datepicker version 2.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin All Category SEO Updater Cross-Site Scripting (0.2.7)
WebLogic Improper Handling of Exceptional Conditions Vulnerability (CVE-2017-5638)
WordPress Plugin FPW Category Thumbnails Multiple Unspecified Vulnerabilities (1.6.7)
Zikula Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2293)