Description
WordPress Plugin Stetic is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Stetic version 1.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
WordPress Plugin Contest Gallery-Photo Contest for WordPress SQL Injection (13.1.0.5)
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3)
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6)
WordPress Plugin sourceAFRICA Cross-Site Scripting (0.1.3)
Oracle Database Server CVE-2010-0900 Vulnerability (CVE-2010-0900)