Description
WordPress Plugin Qualified Electronic Signatures by eID Easy is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Qualified Electronic Signatures by eID Easy version 3.3.0 is affected; prior versions may also be affected.
Remediation
Manually remove the use of Polyfill.io from the plugin, or disable and remove the plugin until a fix is available
References
https://sansec.io/research/polyfill-supply-chain-attack
https://plugins.svn.wordpress.org/eid-easy-qualified-electonic-signature/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Fancy Product Designer-WooCommerce Arbitrary File Upload (4.6.8)
WordPress Plugin Fixedly Media Gallery Cross-Site Scripting (1.3.1)
WordPress Plugin WPtouch 'wptouch_settings' Parameter Cross-Site Scripting (1.9.20)
WordPress Plugin Corner Ad Cross-Site Scripting (1.0.7)
Oracle Database Server CVE-2006-0282 Vulnerability (CVE-2006-0282)