Description
WordPress Plugin Ultimate FAQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import CSV files and create new posts, or export all posts/FAQs. WordPress Plugin Ultimate FAQ version 1.8.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.25 or latest
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-0361)
phpBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-1000419)
WordPress Plugin WP Pipes Unspecified Vulnerability (1.28)
WordPress Plugin Cryptocurrency Widgets-Price Ticker & Coins List Security Bypass (2.4)