Description
WordPress Plugin SI CAPTCHA Anti-Spam was deliberately modified to inject spam ads for payday loans and such in the WP posts of the web sites running the plugin. WordPress Plugin SI CAPTCHA Anti-Spam versions 3.0.1 and 3.0.2 are affected ONLY.
Remediation
Update to plugin version 3.0.3 or latest
References
https://wordpress.org/support/topic/where-did-the-plugin-go-2/
https://plugins.svn.wordpress.org/si-captcha-for-wordpress/trunk/readme.txt
Related Vulnerabilities
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-29477)
WordPress Plugin 2Way VideoCalls and Random Chat-HTML5 Webcam Videochat Cross-Site Scripting (5.2.7)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-3065)
WordPress Plugin Divi Builder Security Bypass (1.2.3)
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Arbitrary File Upload (3.4.3)