Description
WordPress Plugin Testimonial WordPress-AP Custom Testimonial [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Testimonial WordPress-AP Custom Testimonial version 1.4.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.7 or latest
References
Related Vulnerabilities
OpenSSL DEPRECATED: Code Vulnerability (CVE-2015-0290)
WordPress 2.0.6 'Zend_Hash_Del_Key_Or_Index' SQL Injection Vulnerability (0.6.2 - 2.0.6)
MySQL CVE-2019-2596 Vulnerability (CVE-2019-2596)
WordPress Plugin Injectscr Spam Injection (All)
IBM WebSEAL Use of Hard-coded Credentials Vulnerability (CVE-2018-1887)