Description
WordPress Plugin SI CAPTCHA Anti-Spam was deliberately modified to inject spam ads for payday loans and such in the WP posts of the web sites running the plugin. WordPress Plugin SI CAPTCHA Anti-Spam versions 3.0.1 and 3.0.2 are affected ONLY.
Remediation
Update to plugin version 3.0.3 or latest
References
https://wordpress.org/support/topic/where-did-the-plugin-go-2/
https://plugins.svn.wordpress.org/si-captcha-for-wordpress/trunk/readme.txt
Related Vulnerabilities
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5341)
WebLogic CVE-2016-3416 Vulnerability (CVE-2016-3416)
WordPress Plugin WP Datepicker Security Bypass (2.1.0)
WordPress Plugin Claptastic Clap! Button Multiple Cross-Site Scripting Vulnerabilities (1.3)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193)