Description
WordPress Plugin WordPress Social Stream is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite admin options. WordPress Plugin WordPress Social Stream version 1.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.16 or latest
References
https://www.exploit-db.com/exploits/39946/
http://codecanyon.net/item/wordpress-social-stream/2201708?s_rank=15
Related Vulnerabilities
Apache Tomcat Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-12615)
Joomla! Core 1.7.x Cross-Site Scripting (1.7.0 - 1.7.2)
Apache error log escape sequence injection vulnerability
WordPress Other Vulnerability (CVE-2007-3140)
WordPress Plugin Super Interactive Maps for WordPress Arbitrary File Upload (1.9)