Description
WordPress Plugin Pods-Custom Content Types and Fields contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Pods-Custom Content Types and Fields version 3.2.3 is affected.
Remediation
Update back to clean plugin version 3.2.2 or latest
References
Related Vulnerabilities
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0126)
WordPress Plugin Snazzy Archives Cross-Site Scripting (1.7.1)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7903)
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-14251)
Apache Tomcat Deserialization of Untrusted Data Vulnerability (CVE-2020-9484)