A WordPress plug-in installed in more than 1 million websites that was vulnerable to high-severity bugs has been patched. The vulnerabilities would have allowed attackers to export malicious pieces of code or JavaScript to all affected WordPress sites. Attackers can then plant malware, steal data and hijack users to nefarious sites, researchers say. American Express, ClickBank, Pinterest, Experian, Trip Advisor and Harvard University use the OptinMonster Plug-in. The company says 1.2 million websites use it, including American Express and ClickBank.”]
Source: https://www.databreachtoday.com/wordpress-plug-in-bugs-put-1-million-plus-sites-at-risk-a-17822