Description
WordPress Plugin Ad Invalid Click Protector (AICP) contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Ad Invalid Click Protector (AICP) version 1.2.9 is affected.
Remediation
Update to plugin version 1.2.11 or latest
References
Related Vulnerabilities
WordPress Deserialization of Untrusted Data Vulnerability (CVE-2018-19296)
WordPress Plugin Permalink Manager Lite SQL Injection (2.2.12)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (5.3.5)
WordPress Plugin Fancy Product Designer-WooCommerce Cross-Site Scripting (4.5.0)