Description
WordPress Plugin Related Posts Lite is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Related Posts Lite version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.11 or latest
References
Related Vulnerabilities
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-3814)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2016-9451)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-4448)
WordPress Plugin Schreikasten 'name' or 'contact' Field Cross-Site Scripting (0.14.13)