Description
WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite version 1.0.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.9 or latest
References
Related Vulnerabilities
WordPress Plugin Category Grid View Gallery Cross-Site Scripting (2.3.3)
EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2019-14351)
Joomla! Core Directory Traversal (1.5.0 - 3.9.4)
WordPress Plugin WP Coder-add custom html, css and js code SQL Injection (2.5.3)
WordPress Plugin WooCommerce Product Feed Manager Security Bypass (2.2.3)