Description
WordPress Plugin ContentStudio is prone to multiple vulnerabilities, including security bypass and information disclosure vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently retrieve arbitrary metadata, including the plugin's token used in creating a post, or execute functions intended for use by users with proper API keys, or to obtain sensitive information that may help in launching further attacks. WordPress Plugin ContentStudio version 1.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.6 or latest
References
Related Vulnerabilities
Oracle Database Server CVE-2014-6455 Vulnerability (CVE-2014-6455)
SharePoint Improper Input Validation Vulnerability (CVE-2019-1296)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.5)
MySQL CVE-2020-2584 Vulnerability (CVE-2020-2584)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-16335)