Description
WordPress Plugin Pinterest Automatic Pin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently take over the website and its database. WordPress Plugin Pinterest Automatic Pin version 4.14.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 4.14.4 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-pinterest-automatic-plugin/
https://codecanyon.net/item/pinterest-automatic-pin-wordpress-plugin/2203314
Related Vulnerabilities
Oracle Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2001-1371)
WordPress Plugin Catch Sticky Menu Security Bypass (1.6.3)
WordPress Plugin Kraken.io Image Optimizer Cross-Site Request Forgery (2.6.5)
WordPress Plugin Oleggo LiveStream Cross-Site Scripting (0.2.6)