Description
WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete the campaign cache. WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin version 1.2.49.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.50.0 or latest
References
https://wpscan.com/vulnerability/b9154128-2a30-450e-adc1-4c946cf9784f
https://plugins.svn.wordpress.org/mailoptin/trunk/changelog.txt
Related Vulnerabilities
Oracle HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
WordPress Plugin Featurific For WordPress 'snum' Parameter Cross-Site Scripting (1.6.2)
WordPress Plugin SEO Redirection-301 Redirect Manager Unspecified Vulnerability (8.7)
WordPress Plugin Widget Control Powered By Everyblock Cross-Site Scripting (1.0.1)