Description
WordPress Plugin Ajax Search Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Pro version 3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0 or latest
References
http://research.evex.pw/?vuln=9
http://packetstormsecurity.com/files/130955/WordPress-Ajax-Search-Pro-Remote-Code-Execution.html
Related Vulnerabilities
WordPress Plugin wpStoreCart 'upload.php' Arbitrary File Upload (2.5.29)
Drupal Other Vulnerability (CVE-2015-3232)
PHP Other Vulnerability (CVE-2011-3182)
WordPress Plugin Side Menu-add fixed side buttons SQL Injection (3.1.3)
WordPress Plugin Mailster-Email Newsletter for WordPress Cross-Site Scripting (2.4.5.1)