Description
WordPress Plugin Jayj Quicktag is prone to multiple vulnerabilities, including PHP object injection and cross-site request forgery vulnerabilities. A successful exploit may allow an attacker to execute arbitrary PHP code within the context of the affected webserver process or to perform certain administrative actions; other attacks are also possible. WordPress Plugin Jayj Quicktag version 1.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.2 or latest
References
Related Vulnerabilities
WordPress Plugin Thrive Themes Builder Security Bypass (2.2.3)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1818)
Oracle Database Server CVE-2011-0806 Vulnerability (CVE-2011-0806)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.3.2)