Description
WordPress Plugin The Easiest WordPress Media Manager-WP Media Manager Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin The Easiest WordPress Media Manager-WP Media Manager Lite version 1.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (2.3.12)
Rukovoditel Cross-site Scripting (XSS) Vulnerability (CVE-2019-7541)
Oracle Database Server Other Vulnerability (CVE-2005-0297)
WordPress Plugin MAZ Loader-Preloader Builder for WordPress Cross-Site Request Forgery (1.4.0)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0301)