Description
WordPress Plugin PI Button [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin PI Button version 3.3.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.4 or latest
References
Related Vulnerabilities
WordPress Plugin Auto Featured Image Arbitrary File Upload (1.2)
WordPress Plugin Venture Event Manager Cross-Site Scripting (3.2.4)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.4.5)
Oracle Database Server Other Vulnerability (CVE-2006-1869)
Drupal Core 8.9.x Multiple Cross-Site Scripting Vulnerabilities (8.9.0 - 8.9.5)