Description
WordPress Plugin Logo Slider and Showcase is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Logo Slider and Showcase version 1.3.36 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.37 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:8DFC86E4-56A0-4E30-9050-CF3F328FF993
https://plugins.svn.wordpress.org/wp-logo-showcase/trunk/README.txt
Related Vulnerabilities
WordPress 3.3.1 Multiple Vulnerabilities (2.0 - 3.3.1)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2019-4156)
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.3.9)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7128)