Description
WordPress Plugin BCS BatchLine Book Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/update arbitrary products. WordPress Plugin BCS BatchLine Book Importer version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:23B76562-D2AF-4753-BCE4-002921F3378E
https://plugins.svn.wordpress.org/bcs-bertline-book-importer/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Login Security Solution Multiple Unspecified Vulnerabilities (0.50.0)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2359)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0126)
WordPress Plugin WordPress for Google Maps-WP MAPS SQL Injection (4.0.4)