Description
WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Easiest Contact Form for WordPress-AP Contact Form version 1.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-15882)
SharePoint CVE-2017-8509 Vulnerability (CVE-2017-8509)
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2017-7490)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.32)
WordPress Plugin LearnDash LMS Cross-Site Scripting (3.1.1.1)