Description
WordPress Plugin pipdig Power pack (p3) contains suspicious code. Attackers can exploit this issue to perform a variety of actions: reset password, delete database, etc. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin pipdig Power pack (p3) version 4.7.3 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
https://www.wordfence.com/blog/2019/03/peculiar-php-present-in-popular-pipdig-power-pack-plugin/
https://www.jemjabella.co.uk/2019/security-alert-pipdig-insecure-ddosing-competitors/
Related Vulnerabilities
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.14)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.5)
Oracle Application Server CVE-2006-3711 Vulnerability (CVE-2006-3711)
WordPress Plugin Simple Banner Cross-Site Scripting (2.11.0)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-5045)