Description
WordPress Plugin Digital River Global Commerce is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin Digital River Global Commerce version 2.0.2 is affected; prior versions may also be affected.
Remediation
Manually remove the use of Polyfill.io from the plugin, or disable and remove the plugin until a fix is available
References
https://sansec.io/research/polyfill-supply-chain-attack
https://wordpress.org/plugins/digital-river-global-commerce/#description
Related Vulnerabilities
Oracle Application Server CVE-2009-0983 Vulnerability (CVE-2009-0983)
Django Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-31542)
WordPress Plugin VK All in One Expansion Unit Cross-Site Scripting (9.85.0.1)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35614)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-36125)