Description
WordPress Plugin Browsealoud includes JavaScript code that would mine cryptocurrency using the CPU resources of site visitors. This allows the attacker to earn money by using the CPU resources of visitors. WordPress Plugin Browsealoud version 1.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Ultimate SMS Notifications for WooCommerce CSV Injection (1.4.1)
WordPress Plugin Advanced Classifieds & Directory Pro Unspecified Vulnerability (1.6.5)
WordPress Plugin Donation Block For PayPal Unspecified Vulnerability (1.0.0)
WordPress Plugin Gantry 5 Framework Cross-Site Scripting (5.4.8)