Description
WordPress Plugin WP Popup Lite-Responsive popup for WordPress [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin WP Popup Lite-Responsive popup for WordPress version 1.0.8 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin, or download it from wordpress.org repository
References
Related Vulnerabilities
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5485)
WordPress Plugin Follow Me Cross-Site Request Forgery (3.1.1)
WordPress Plugin NextGEN Gallery Sell Photo Cross-Site Scripting (1.0.4)
Oracle Application Server CVE-2006-0291 Vulnerability (CVE-2006-0291)