Description
WordPress Plugin Dropshix is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create spam pages. WordPress Plugin Dropshix version 4.0.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.14 or latest
References
Related Vulnerabilities
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8707)
Drupal Core 8.7.0 Directory Traversal (8.7.0)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3390)
WordPress Plugin WordPress Leads Unspecified Vulnerability (1.6.8)
WordPress Plugin Ajax Search Lite Remote Command Execution (3.1)