Description
WordPress Plugin Search Exclude is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin Search Exclude version 1.2.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.5 or latest
References
https://www.pluginvulnerabilities.com/2019/09/03/settings-change-vulnerability-in-search-exclude/
https://blog.nintechnet.com/settings-change-vulnerability-in-wordpress-search-exclude-plugin/
https://plugins.svn.wordpress.org/search-exclude/trunk/readme.txt
Related Vulnerabilities
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-9787)
WordPress Plugin GEO Redirector Cross-Site Scripting (1.0.1)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.7.0 - 3.9.18)
WordPress Plugin WP-Print Cross-Site Request Forgery (2.51)
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9)