Description
WordPress Plugin Convert Plus is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create new accounts. WordPress Plugin Convert Plus version 3.4.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.5 or latest
References
Related Vulnerabilities
WordPress Plugin BuddyPress Activity Plus Cross-Site Scripting (1.6.3)
WordPress Plugin Essential Blocks Pro Multiple PHP Object Injection Vulnerabilities (1.1.0)
WordPress Plugin Wufoo Shortcode Cross-Site Scripting (1.51)
WordPress Plugin Tickera-WordPress Event Ticketing Cross-Site Request Forgery (3.5.1.0)