Description
WordPress Plugin Alphabetic Pagination is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugins's settings and allow registration with a default role of administrator. WordPress Plugin Alphabetic Pagination version 3.0.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:3D72B705-F1AB-4E20-AA2D-426B3151EEEA
https://plugins.svn.wordpress.org/alphabetic-pagination/trunk/readme.txt
Related Vulnerabilities
Atlassian Confluence Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2928)
MySQL Other Vulnerability (CVE-2012-5383)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.3)
OpenSSL Cryptographic Issues Vulnerability (CVE-2009-2409)
WordPress Plugin FourSquare Checkins Cross-Site Request Forgery (1.2)