Description
WordPress Plugin Facebook-this is injecting "goo.gl" spam links into the website's content, thus publicizing external websites to search engines without the authorization of the website's owner. WordPress Plugin Facebook-this version 2.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL CVE-2017-3653 Vulnerability (CVE-2017-3653)
WordPress Plugin JW Player for Flash & HTML5 Video Cross-Site Request Forgery (2.1.11)
WordPress Plugin RSS Includes Pages Cross-Site Scripting (3.6)
Oracle JRE CVE-2014-0455 Vulnerability (CVE-2014-0455)
WordPress Plugin wpForo Forum Multiple Vulnerabilities (2.1.7)