Description
WordPress Plugin Wrapper Link Elementor contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Wrapper Link Elementor versions 1.0.2 - 1.0.3 are affected.
Remediation
Update to plugin version 1.0.5 or latest
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2007-2509)
XWiki Missing Authorization Vulnerability (CVE-2024-43401)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1862)
WordPress Plugin Real WYSIWYG 'insert_file.php' Arbitrary File Upload (0.0.2)
Dolibarr Improper Privilege Management Vulnerability (CVE-2020-14201)