Description
WordPress Plugin Browsealoud includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the attacker to earn money by using the CPU resources of visitors. WordPress Plugin Browsealoud version 1.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Forminator-Contact Form, Payment Form & Custom Form Builder SQL Injection (1.29.2)
WordPress Plugin Link Juice Keeper Cross-Site Scripting (2.0.2)
WordPress Plugin Popup Like box-Page SQL Injection (3.5.2)
WordPress Plugin Apptivo eCommerce Multiple Cross-Site Scripting Vulnerabilities (1.1.5)