Description
WordPress Plugin Digital Climate Strike WP is prone to malicious redirects. Attackers may leverage this issue to promote spam, distribute malware/backdoors, or to perform all kinds of malicious activities. WordPress Plugin Digital Climate Strike WP version 1.0.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://wordpress.org/support/topic/plugin-loads-compromised-asset/
https://wordpress.org/plugins/digital-climate-strike-wp/#description
Related Vulnerabilities
WordPress Plugin Resize Image After Upload Cross-Site Request Forgery (1.8.5)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.8)
MongoDb Improper Handling of Exceptional Conditions Vulnerability (CVE-2020-7923)
WordPress Plugin Convert Plus Security Bypass (3.4.2)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-31778)