Description
WordPress Plugin WP Floating Menu-One page navigator, sticky menu for WordPress [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin WP Floating Menu-One page navigator, sticky menu for WordPress version 1.4.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.5 or latest
References
Related Vulnerabilities
PHP Out-of-bounds Read Vulnerability (CVE-2017-16642)
Undertow Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-3859)
WordPress Plugin Advertizer 'id' Parameter SQL Injection (1.0)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)
WordPress Plugin Image Slider by Ays-Responsive Slider and Carousel SQL Injection (2.4.9)