Description
WordPress Plugin WP Import Export Lite is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently set/disable the extensions used by the plugin, or update the blog options. WordPress Plugin WP Import Export Lite version 3.9.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.9.5 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:B5A8A4D1-61D9-46DD-8F52-321758172788
https://sploitus.com/exploit?id=WPEX-ID:28B06084-67A0-466D-8030-5FEDDBAFDFE2
http://plugins.vjinfotech.com/wordpress-import-export/change-log/
Related Vulnerabilities
WordPress Plugin WordPress Colorbox Lightbox Cross-Site Scripting (1.1.2)
Drupal Core 4.6.x Session Fixation (4.6.0 - 4.6.5)
WordPress Plugin One page checkout and layouts for woocommerce Unspecified Vulnerability (2.7)
WordPress Plugin WooCommerce Possible Remote Code Execution (3.5.0)
WordPress Plugin Hustle-Pop-Ups, Slide-ins and Email Opt-ins Cross-Site Scripting (4.7.0.5)