Description
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
Remediation
References
Related Vulnerabilities
WordPress Plugin Canto Multiple Server-Side Request Forgery Vulnerabilities (1.7.0)
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Request Forgery (4.3.6)
WordPress Plugin WP Statistics Multiple Cross-Site Scripting Vulnerabilities (12.0.4)
WordPress Plugin Slideshow Multiple Cross-Site Scripting Vulnerabilities (2.1.14)