Description
WordPress Plugin Apocalypse Meow is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass Bcrypt authentication mechanism. WordPress Plugin Apocalypse Meow versions starting from 21.1.3 and up to, and including 21.2.7 are vulnerable.
Remediation
Update to plugin version 21.2.8 or latest
References
https://twitter.com/Sc00bzT/status/937124418500866048
https://plugins.svn.wordpress.org/apocalypse-meow/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Multisite Plugin Manager Multiple Cross-Site Scripting Vulnerabilities (3.1.1)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3663)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5498)
WordPress Plugin CodeArt-Google MP3 Player Arbitrary File Disclosure (1.0.11)
WordPress Plugin Swiss Toolkit For WP Security Bypass (1.0.8)