Description
WordPress Plugin WatchTowerHQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download/delete arbitrary files. WordPress Plugin WatchTowerHQ version 3.6.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.6.16 or latest
References
Related Vulnerabilities
WordPress Plugin Frontend File Manager Arbitrary File Upload (3.3)
WordPress Plugin AccessPress Social Icons SQL Injection (1.8.0)
WordPress Plugin Global Content Blocks Cross-Site Request Forgery (2.1.5)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7871)
Liferay DXP Incorrect Authorization Vulnerability (CVE-2021-33335)