Description
WordPress Plugin WP Popup Banners [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin WP Popup Banners version 1.2.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.4 or latest
References
Related Vulnerabilities
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5383)
WordPress Plugin Slider Hero with Animation, Video Background Cross-Site Request Forgery (8.2.0)
PHP Out-of-bounds Read Vulnerability (CVE-2018-20783)
MongoDb Improper Input Validation Vulnerability (CVE-2018-20804)
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2016-7137)