Description
WordPress Plugin ThinkTwit is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently write to the images folder. WordPress Plugin ThinkTwit version 1.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.2 or latest
References
Related Vulnerabilities
WordPress Plugin Widget Logic Cross-Site Request Forgery (5.9.0)
WordPress Plugin Meta Box-WordPress Custom Fields Framework Arbitrary File Deletion (4.16.2)
WordPress Plugin WooCommerce Product Attachment Cross-Site Scripting (1.1.2)
WordPress Plugin Contus HD FLV Player 'uploadVideo.php' Arbitrary File Upload (1.7)