Description
WordPress Plugin WPGateway is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WPGateway version 3.5 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7912)
WordPress Plugin Realteo Multiple Vulnerabilities (1.2.3)
MySQL CVE-2013-0368 Vulnerability (CVE-2013-0368)
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-11322)
WordPress Plugin LearnDash LMS Arbitrary File Upload (2.5.3)