Description
WordPress Plugin WP Popup Lite-Responsive popup for WordPress [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin WP Popup Lite-Responsive popup for WordPress version 1.0.8 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin, or download it from wordpress.org repository
References
Related Vulnerabilities
Oracle Database Server CVE-2010-0903 Vulnerability (CVE-2010-0903)
WordPress 4.0.x Possible SQL Injection Vulnerability (4.0 - 4.0.19)
ownCloud Improper Authentication Vulnerability (CVE-2016-9463)
WordPress Plugin Gravity Upload Ajax Arbitrary File Upload (1.1)
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000394)