[ad_1]
Third attempt to post this and get around the aut0 m0derat0r.
A plugin injected a banner that contained JS that changed all the URLs within/wp-admin/. This seems like a pretty big WP security hole. I am not sure how WP fences those banners, but it looks like it may need to be tightened.
Is there a plugin that blocks advertising (external) banners from being injected into the site? I searched but I didn’t see any that were that granular.
[ad_2]
No, there is no plugin that prevents malicious plugins from being malicious. Only use trusted and vetted plugins.