Description
WordPress Plugin Digital Climate Strike WP is prone to malicious redirects. Attackers may leverage this issue to promote spam, distribute malware/backdoors, or to perform all kinds of malicious activities. WordPress Plugin Digital Climate Strike WP version 1.0.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://wordpress.org/support/topic/plugin-loads-compromised-asset/
https://wordpress.org/plugins/digital-climate-strike-wp/#description
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2005-0799)
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-19138)
WordPress Plugin WooCommerce Cross-Site Scripting (2.2.10)
MySQL CVE-2013-3811 Vulnerability (CVE-2013-3811)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-11586)