Description
WordPress Plugin Catch Duplicate Switcher is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin's configuration. WordPress Plugin Catch Duplicate Switcher version 1.5.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:181A729E-FFFE-457C-9E8D-A4343FD2E630
https://plugins.svn.wordpress.org/catch-duplicate-switcher/trunk/README.txt
Related Vulnerabilities
WordPress Plugin ZdStatistics Cross-Site Scripting (2.0.1)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Cross-Site Request Forgery (1.1.90)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6926)
WordPress Plugin Animate It! Cross-Site Request Forgery (2.3.5)