Description
WordPress Plugin PWA for WP & AMP is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin�s settings, or even upload arbitrary files. WordPress Plugin PWA for WP & AMP version 1.7.32 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.33 or latest
References
Related Vulnerabilities
WordPress Plugin Free counter Cross-Site Scripting (1.1)
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Arbitrary File Upload (1.2.1)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-4724)
WordPress Plugin ForumConverter SQL Injection (1.11)
WordPress Plugin Party Hall Booking Manager SQL Injection (1.1)