Description
WordPress Plugin Simply Show Hooks contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Simply Show Hooks version 1.2.1 is affected; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin LeagueManager Multiple SQL Injection Vulnerabilities (3.9.1.1)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-10545)
Oracle Database Server CVE-2011-0875 Vulnerability (CVE-2011-0875)
WordPress Plugin AVK-Shop Multiple Cross-Site Scripting Vulnerabilities (1.1.1)