Description
WordPress Plugin Free WordPress To Display Like/Dislike Comment Rating-Everest Comment Rating Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Free WordPress To Display Like/Dislike Comment Rating-Everest Comment Rating Lite version 2.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.4.1)
Drupal Core 5.x Local File Inclusion (5.0 - 5.11)
WordPress Plugin ShareYourCart Information Disclosure (1.6.1)
Joomla Cryptographic Issues Vulnerability (CVE-2014-7228)
WordPress Plugin Nelio AB Testing Server-Side Request Forgery (4.5.10)