Description
WordPress Plugin BLAZE Retail Widget contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin BLAZE Retail Widget versions 2.2.5 - 2.5.2 are affected.
Remediation
Update to plugin version 2.5.4 or latest
References
Related Vulnerabilities
WordPress Plugin Link Juice Keeper Cross-Site Scripting (2.0.2)
Internet Information Services Other Vulnerability (CVE-2002-0071)
Dolibarr CVE-2019-11200 Vulnerability (CVE-2019-11200)
WordPress Plugin Custom Search by BestWebSoft Unspecified Vulnerability (1.21)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-27903)