Description
WordPress Plugin Total GDPR Compliance Lite-WordPress for GDPR Compatibility [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Total GDPR Compliance Lite-WordPress for GDPR Compatibility version 1.0.4 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin, or download it from wordpress.org repository
References
Related Vulnerabilities
Python Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20907)
WordPress Plugin Gallery-Flagallery Photo Portfolio 'flagshow.php' Cross-Site Scripting (1.57)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2016-7052)
WordPress Plugin KNR Author List Widget 'listItem[]' Parameter SQL Injection (2.0.0)