Description
WordPress Plugin Facebook-this is injecting "goo.gl" spam links into the website's content, thus publicizing external websites to search engines without the authorization of the website's owner. WordPress Plugin Facebook-this version 2.5 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Enable Media Replace SQL Injection and Arbitrary File Upload Vulnerabilities (2.3)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.9.63)
ProjectSend Improper Privilege Management Vulnerability (CVE-2020-28874)
Apache Tomcat Other Vulnerability (CVE-2011-1088)
Oracle JRE Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3174)