Description
WordPress Plugin Browsealoud includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the attacker to earn money by using the CPU resources of visitors. WordPress Plugin Browsealoud version 1.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Duplicator-WordPress Migration Cross-Site Scripting (0.5.26)
Opencart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-47444)
WordPress Plugin Payment Gateways Caller for WP e-Commerce Local File Inclusion (0.1)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-6664)