Description
WordPress Plugin BLAZE Retail Widget contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin BLAZE Retail Widget versions 2.2.5 - 2.5.2 are affected.
Remediation
Update to plugin version 2.5.4 or latest
References
Related Vulnerabilities
WordPress Plugin Keyword Meta Cross-Site Request Forgery (3.0)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2016-2098)
WordPress Plugin WP-Matomo (WP-Piwik) Unspecified Vulnerability (1.0.18)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.12)
Oracle Database Server CVE-2011-2301 Vulnerability (CVE-2011-2301)