Description
WordPress Plugin WordPress Social Stream is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite admin options. WordPress Plugin WordPress Social Stream version 1.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.16 or latest
References
https://www.exploit-db.com/exploits/39946/
http://codecanyon.net/item/wordpress-social-stream/2201708?s_rank=15
Related Vulnerabilities
WordPress Plugin Salon Booking System Arbitrary File Upload (10.2)
Oracle Application Server Other Vulnerability (CVE-2007-0282)
WordPress Plugin Print-O-Matic Cross-Site Scripting (2.1.7)
WordPress Plugin Cartogiraffe Map Cross-Site Scripting (1.0)
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842)