Description
WordPress Plugin Backup Bank:WordPress Backup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Backup Bank:WordPress Backup version 4.0.28 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Comment Highlighter SQL Injection (0.13)
WordPress Plugin Advanced Access Manager Cross-Site Scripting (6.7.9)
Joomla! Core 3.x.x Security Bypass (3.8.8 - 3.9.16)
WordPress Plugin eHive Object Details Cross-Site Scripting (2.1.6)
WordPress Plugin Flat Preloader Cross-Site Request Forgery (1.5.3)