Description
WordPress Plugin WPCOM Member contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin WPCOM Member version 1.3.16 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.3.17 or latest
References
Related Vulnerabilities
Zope Web Application Server Other Vulnerability (CVE-2001-1278)
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-2099)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress SQL Injection (3.11.1)
Oracle HTTP Server CVE-2022-21593 Vulnerability (CVE-2022-21593)
Python Uncontrolled Resource Consumption Vulnerability (CVE-2022-45061)