Description
WordPress Plugin Injectbody is injecting spam into the website's content, in form of pop-ups, thus serving questionable ads to visitors without the authorization of the website's owner. WordPress Plugin Injectbody all version are vulnerable.
Remediation
Disable the plugin
References
https://blog.sucuri.net/2018/02/unwanted-popups-caused-injectbody-injectscr-plugins.html
https://wordpress.org/support/topic/wordfence-fail-didnt-find-malicious-plugin/
Related Vulnerabilities
IBM RTC Cross-site Scripting (XSS) Vulnerability (CVE-2020-4691)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20099)
Play Framework Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-12480)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9449)
WordPress Plugin Pinterest Automatic Pin Security Bypass (4.14.3)