Description
WordPress Plugin BLAZE Retail Widget contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin BLAZE Retail Widget versions 2.2.5 - 2.5.2 are affected.
Remediation
Update to plugin version 2.5.4 or latest
References
Related Vulnerabilities
MySQL CVE-2020-14765 Vulnerability (CVE-2020-14765)
XWiki Insufficiently Protected Credentials Vulnerability (CVE-2022-41933)
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7324)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2271)