Description
WordPress Plugin WPCOM Member contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin WPCOM Member version 1.3.16 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.3.17 or latest
References
Related Vulnerabilities
MySQL CVE-2017-3644 Vulnerability (CVE-2017-3644)
Oracle Database Server CVE-2010-3590 Vulnerability (CVE-2010-3590)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9546)
Joomla Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2018-11325)
Moodle Improper Input Validation Vulnerability (CVE-2013-2083)