Display Widgets < 2.7 - SEO Spam Injection (Hidden Functionality)
2017-06-23 00:00
AnonymousStrategic Overview
Vulnerability Overview
The Display Widgets plugin for WordPress is vulnerable to a developer-created backdoor that injected SEOspam into sites in versions up to, and including, 2.6.3.1. Any added content is hidden from logged-in users.
Technical Analysis
REMEDIATION: Update to version 2.7, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C