Description
WordPress Plugin Event Single Page Templates Addon For The Events Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download and extract a remote ZIP file on the blog, which can lead to remote code execution. WordPress Plugin Event Single Page Templates Addon For The Events Calendar version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
Related Vulnerabilities
WordPress Plugin Embed Swagger Cross-Site Scripting (1.0.0)
WordPress Plugin Simple Gmail Login Stack Trace Information Disclosure (1.1.3)
Drupal Core 4.7.x Multiple Vulnerabilities (4.7.0 - 4.7.1)
WordPress Plugin WORDPRESS VIDEO GALLERY Open Email Relay (2.8)
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist Arbitrary File Upload (2.0)