Description
WordPress Plugin Batch Cat is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add/set/delete arbitrary categories to posts. WordPress Plugin Batch Cat version 0.3 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Jboss EAP Improper Input Validation Vulnerability (CVE-2011-4314)
WordPress Plugin AppPresser-Mobile App Framework Security Bypass (4.3.2)
Oracle Database Server CVE-2008-2602 Vulnerability (CVE-2008-2602)
WordPress Plugin Contact Form by Supsystic Cross-Site Scripting (1.7.19)
WordPress Plugin Custom Post Type UI 'wp-admin/admin.php' Cross-Site Scripting (0.7)