Description
WordPress Plugin WP-Syntax is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin WP-Syntax versions 0.9.9 and prior are affected.
Remediation
Update to plugin version 0.9.10 or latest
References
Related Vulnerabilities
WordPress Plugin OMGF-Host Google Fonts Locally Multiple Vulnerabilities (4.5.3)
WordPress Plugin WP-Spreadplugin Multiple Vulnerabilities (4.4.4)
Joomla Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-15699)
WordPress Plugin WassUp Real Time Analytics 'spy.php' SQL Injection (1.4.3)