Description
WordPress Plugin Logo Slider and Showcase is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Logo Slider and Showcase version 1.3.36 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.37 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:8DFC86E4-56A0-4E30-9050-CF3F328FF993
https://plugins.svn.wordpress.org/wp-logo-showcase/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Participants Database SQL Injection (1.5.4.8)
Drupal Core 7.x Directory Traversal (7.0 - 7.66)
Oracle JRE CVE-2020-2593 Vulnerability (CVE-2020-2593)
SharePoint CVE-2021-27076 Vulnerability (CVE-2021-27076)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-36125)