A WordPress plugin named Convert Plus has a critical bug which can literally throw the baby with the bath water. Convert Plus plugin provides a WordPress website with lead-generation capability, which it claims to capture more users and traffic to the site for the long term. The vulnerable version of Convert Plus provides external user the capability to receive an administrator-level account when trying to submit a form for new user creation for the website. The vulnerability came from the cp_set_user value which is in a hidden field, that value can be modified by an outsider.”]
Source: https://hackercombat.com/wordpress-plugins-administrator-creation-bug-disclosed/

