Description
WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite version 1.0.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.9 or latest
References
Related Vulnerabilities
WordPress 'wp-login.php' HTTP Response Splitting Vulnerability (1.2 - 1.2)
WordPress 4.7.x Cross-Domain Flash Injection Vulnerability (4.7 - 4.7.8)
WordPress Plugin Contact Form by BestWebSoft Cross-Site Scripting (3.34)
WordPress Plugin Cashtomer SQL Injection (1.0.0)
WordPress Plugin Digital Publications by Supsystic Multiple Vulnerabilities (1.6.9)