Description
WordPress Plugin Stylish Price List is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently upload arbitrary images. WordPress Plugin Stylish Price List version 6.8.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.9.0 or latest
References
Related Vulnerabilities
Rukovoditel Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11815)
ZenCart Improper Authentication Vulnerability (CVE-2009-2255)
Oracle Database Server CVE-2006-5339 Vulnerability (CVE-2006-5339)
Drupal Core 8.x.x Multiple Security Bypass Vulnerabilities (8.0.0 - 8.8.12)
WordPress Plugin Gallery PhotoBlocks Unspecified Vulnerability (1.1.32)