Description
WordPress Plugin Wrapper Link Elementor contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Wrapper Link Elementor versions 1.0.2 - 1.0.3 are affected.
Remediation
Update to plugin version 1.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin Theme Demo Import Arbitrary File Upload (1.1.0)
WordPress Plugin Tweet Blender Cross-Site Scripting (4.0.1)
WordPress 2.3 Cross-Site Scripting Vulnerability (2.3)
TYPO3 CVE-2024-25119 Vulnerability (CVE-2024-25119)
Ruby on Rails Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-5419)