Description
WordPress Plugin Responsive WordPress Timeline-Everest Timeline Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Responsive WordPress Timeline-Everest Timeline Lite version 1.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin Yandex Money button Cross-Site Scripting (2.3.3)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670)
WordPress Plugin Social Sharing-Sassy Social Share Cross-Site Scripting (3.3.3)
WordPress Plugin My Tickets Security Bypass (1.9.11)
Magento Improper Authentication Vulnerability (CVE-2015-3457)