Description
WordPress Plugin Injectscr is injecting spam into the website's content, in form of pop-ups, thus serving questionable ads to visitors without the authorization of the website's owner. WordPress Plugin Injectscr all version are vulnerable.
Remediation
Disable the plugin
References
https://blog.sucuri.net/2018/02/unwanted-popups-caused-injectbody-injectscr-plugins.html
https://wordpress.org/support/topic/wordfence-fail-didnt-find-malicious-plugin/
Related Vulnerabilities
WordPress Plugin Search & Replace SQL Injection (3.2.1)
WordPress Plugin FormBuilder Cross-Site Scripting (1.05)
WordPress Plugin MP3-jPlayer Multiple Cross-Site Request Forgery Vulnerabilities (2.7.3)
WordPress Plugin WP Sitemap Page Cross-Site Scripting (1.6.4)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-37911)