Description
WordPress Plugin Product Catalog is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Product Catalog version 3.8.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.8.2 or latest
References
https://www.exploit-db.com/exploits/39974/
https://wordpress.org/plugins/ultimate-product-catalogue/changelog/
Related Vulnerabilities
Ruby on Rails Improper Input Validation Vulnerability (CVE-2016-2098)
WordPress Plugin WP-Backgrounds Lite Cross-Site Request Forgery (2.3)
Oracle Database Server CVE-2013-3760 Vulnerability (CVE-2013-3760)
OpenSSL Cryptographic Issues Vulnerability (CVE-2008-7270)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (1.7.0)