Description
WordPress Plugin Convert Plus is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create new accounts. WordPress Plugin Convert Plus version 3.4.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.5 or latest
References
Related Vulnerabilities
Oracle Database Server CVE-2013-3790 Vulnerability (CVE-2013-3790)
FrontAccounting Multiple SQL Injection Vulnerabilities (CVE-2014-3973)
Piwigo Improper Access Control Vulnerability (CVE-2016-10514)
WordPress Plugin Name Directory Cross-Site Request Forgery (1.17.4)
Liferay Portal CVE-2020-13444 Vulnerability (CVE-2020-13444)