Description
WordPress Plugin GA Top post for WP by Asentechllc is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently upload files with .p12 extension. WordPress Plugin GA Top post for WP by Asentechllc version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0714)
WordPress Possible SQL Injection Vulnerability (0.70 - 3.6.1)
WordPress Plugin Shopping Cart & eCommerce Store Arbitrary File Upload (3.0.8)
Joomla CVE-2019-12764 Vulnerability (CVE-2019-12764)
Oracle Application Server CVE-2004-1368 Vulnerability (CVE-2004-1368)