Description
WordPress Plugin Digital Climate Strike WP is prone to malicious redirects. Attackers may leverage this issue to promote spam, distribute malware/backdoors, or to perform all kinds of malicious activities. WordPress Plugin Digital Climate Strike WP version 1.0.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://wordpress.org/support/topic/plugin-loads-compromised-asset/
https://wordpress.org/plugins/digital-climate-strike-wp/#description
Related Vulnerabilities
WordPress Plugin Woody ad snippets-Insert Header Footer Code, AdSense Ads PHP Code Injection (1.3)
WordPress Plugin Contact Form for WordPress-Ultimate Form Builder Lite Cross-Site Scripting (1.3.3)
MediaWiki Credentials Management Errors Vulnerability (CVE-2015-8009)
PHP Resource Management Errors Vulnerability (CVE-2011-1468)