Description
WordPress Plugin Injectscr is injecting spam into the website's content, in form of pop-ups, thus serving questionable ads to visitors without the authorization of the website's owner. WordPress Plugin Injectscr all version are vulnerable.
Remediation
Disable the plugin
References
https://blog.sucuri.net/2018/02/unwanted-popups-caused-injectbody-injectscr-plugins.html
https://wordpress.org/support/topic/wordfence-fail-didnt-find-malicious-plugin/
Related Vulnerabilities
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7117)
Piwigo CVE-2014-4648 Vulnerability (CVE-2014-4648)
Telerik Web UI Missing Authorization Vulnerability (CVE-2021-28141)
Drupal Core 8.7.x Security Bypass (8.7.0 - 8.7.10)
WordPress Plugin Last.fm Rotation Local File Inclusion (1.0)