Description
WordPress Plugin PHP Everywhere is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently make themselves administrators and execute PHP code. WordPress Plugin PHP Everywhere version 1.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4 or latest
References
Related Vulnerabilities
IBM RTC Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-29844)
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-43560)
WordPress Plugin Async JavaScript Cross-Site Scripting (2.20.12.09)
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2019-15043)
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0247)