Description
WordPress Plugin MContact Button [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin MContact Button version 2.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.7 or latest
References
Related Vulnerabilities
OpenVPN AS Improper Authentication Vulnerability (CVE-2020-15077)
WordPress Plugin Poll Maker Cross-Site Scripting (3.2.8)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-0217)
WordPress Plugin Calendar Unspecified Vulnerability (1.3.10)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5495)