Description
WordPress Plugin Pods-Custom Content Types and Fields contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Pods-Custom Content Types and Fields version 3.2.3 is affected.
Remediation
Update back to clean plugin version 3.2.2 or latest
References
Related Vulnerabilities
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Multiple Vulnerabilities (3.7.0)
WordPress Plugin Contextual Related Posts Cross-Site Request Forgery (1.8.6)
WordPress Plugin WP-UserOnline Cross-Site Scripting (2.88.0)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)
MediaWiki Improper Access Control Vulnerability (CVE-2012-4379)