Description
WordPress Plugin Pinterest Automatic Pin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently take over the website and its database. WordPress Plugin Pinterest Automatic Pin version 4.14.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 4.14.4 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-pinterest-automatic-plugin/
https://codecanyon.net/item/pinterest-automatic-pin-wordpress-plugin/2203314
Related Vulnerabilities
WordPress Plugin Word of the day Arbitrary File Upload (1.0)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0061)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3796)
WordPress 2.3.1 Unauthorized Post Access Vulnerability (2.3.1)
WordPress Plugin WP Mail SMTP by WPForms Cross-Site Scripting (1.3.3)