Description
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress version 1.6.23 is affected; prior versions may also be affected.
Remediation
Manually remove the use of Polyfill.io from the plugin, or disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Favicon by RealFaviconGenerator Cross-Site Scripting (1.3.20)
WordPress Plugin Slider by 10Web-Responsive Image Slider Unspecified Vulnerability (1.1.9)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Cross-Site Scripting (1.1.46)
WordPress Plugin Pinpoint Booking System-#1 WordPress Booking SQL Injection (2.9.9.2.8)