Description
WordPress Plugin Apocalypse Meow is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass Bcrypt authentication mechanism. WordPress Plugin Apocalypse Meow versions starting from 21.1.3 and up to, and including 21.2.7 are vulnerable.
Remediation
Update to plugin version 21.2.8 or latest
References
https://twitter.com/Sc00bzT/status/937124418500866048
https://plugins.svn.wordpress.org/apocalypse-meow/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler SQL Injection (6.3.0)
WordPress Plugin My Tickets Cross-Site Scripting (1.8.30)
WordPress Plugin MSMC-Redirect After Comment Multiple Vulnerabilities (2.1.2)
WordPress Plugin HDW Player (Video Player & Video Gallery) SQL Injection (2.4.2)