Description
WordPress Plugin Injectscr is injecting spam into the website's content, in form of pop-ups, thus serving questionable ads to visitors without the authorization of the website's owner. WordPress Plugin Injectscr all version are vulnerable.
Remediation
Disable the plugin
References
https://blog.sucuri.net/2018/02/unwanted-popups-caused-injectbody-injectscr-plugins.html
https://wordpress.org/support/topic/wordfence-fail-didnt-find-malicious-plugin/
Related Vulnerabilities
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-21027)
Oracle Database Server CVE-2010-2391 Vulnerability (CVE-2010-2391)
WordPress Plugin PayGreen-Ancienne version Cross-Site Request Forgery (4.10.2)
WordPress 4.4.x Prototype Pollution (4.4 - 4.4.26)
WordPress Plugin Qtranslate Slug Unspecified Vulnerability (1.1.16)