Description
WordPress Plugin Ultimate FAQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import CSV files and create new posts, or export all posts/FAQs. WordPress Plugin Ultimate FAQ version 1.8.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.25 or latest