Description
WordPress Plugin Simply Show Hooks contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Simply Show Hooks version 1.2.1 is affected; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin SP Project & Document Manager Unspecified Vulnerability (2.5.8.0)
WordPress 2.2 Cross-Site Scripting Vulnerability (2.2)
WordPress Plugin Geo Mashup Unspecified Vulnerability (1.10.3)
Nginx CVE-2023-27729 Vulnerability (CVE-2023-27729)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-17267)