Description
WordPress Plugin WP Data Access is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WP Data Access version 5.3.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.3.8 or latest
References
Related Vulnerabilities
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.13)
WordPress Plugin Prevent files/folders access Cross-Site Request Forgery (1.1.1)
PHP Other Vulnerability (CVE-2007-1411)
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0256)
WordPress Plugin Greg's High Performance SEO Cross-Site Scripting (1.6.1)