Description
WordPress Plugin WordPress Social Stream is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite admin options. WordPress Plugin WordPress Social Stream version 1.5.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.16 or latest
References
https://www.exploit-db.com/exploits/39946/
http://codecanyon.net/item/wordpress-social-stream/2201708?s_rank=15
Related Vulnerabilities
PHP-Fusion Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1807)
Oracle JRE CVE-2013-1480 Vulnerability (CVE-2013-1480)
WordPress Plugin QIWI payment module for Woocommerce Cross-Site Scripting (0.0.9)
Squid Improper Input Validation Vulnerability (CVE-2009-2855)
WordPress Plugin Sendit WP Newsletter 'submit.php' Blind SQL Injection (1.5.9)