Description
WordPress Plugin Alphabetic Pagination is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugins's settings and allow registration with a default role of administrator. WordPress Plugin Alphabetic Pagination version 3.0.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:3D72B705-F1AB-4E20-AA2D-426B3151EEEA
https://plugins.svn.wordpress.org/alphabetic-pagination/trunk/readme.txt
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2007-4784)
MySQL CVE-2019-2819 Vulnerability (CVE-2019-2819)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-6819)
WordPress Plugin WP-StarsRateBox 'j' Parameter SQL Injection (1.1)
WordPress Ultimate Member Plugin CVE-2020-36170 Vulnerability (CVE-2020-36170)