Description
WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete the campaign cache. WordPress Plugin Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, Aweber-MailOptin version 1.2.49.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.50.0 or latest
References
https://wpscan.com/vulnerability/b9154128-2a30-450e-adc1-4c946cf9784f
https://plugins.svn.wordpress.org/mailoptin/trunk/changelog.txt
Related Vulnerabilities
WebLogic Incorrect Authorization Vulnerability (CVE-2018-1258)
WordPress Plugin Tags Cloud Manager Cross-Site Scripting (1.0.0)
WordPress Plugin Easy Property Listings Unspecified Vulnerability (2.0)
WordPress Plugin Contact Form 7-PayPal Add-on Cross-Site Request Forgery (1.3.4)
WordPress Plugin Page Generator Cross-Site Scripting (1.5.8)