Description
WordPress Plugin WatchTowerHQ is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download/delete arbitrary files. WordPress Plugin WatchTowerHQ version 3.6.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.6.16 or latest
References
Related Vulnerabilities
WordPress Plugin Mailster-Email Newsletter for WordPress Cross-Site Scripting (2.4.5.1)
WordPress Plugin NextGEN Gallery-WordPress Gallery Arbitrary File Upload (1.9.12)
WordPress Plugin CMS Tree Page View Multiple Vulnerabilities (1.4)
Apache Traffic Server Resource Management Errors Vulnerability (CVE-2016-5396)