Description
WordPress Plugin Inline Call To Action Builder Lite-Free Call To Action Layer for WordPress [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Inline Call To Action Builder Lite-Free Call To Action Layer for WordPress version 1.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP eCommerce Multiple Vulnerabilities (3.8.9.5)
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23618)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.2.1)
WordPress Plugin Contact Form 7 International Sms Integration Cross-Site Scripting (1.2)