Social Media Widget 4.0 - Spam Link Injection
Strategic Overview
- Status
- Patched in 4.0.1
- Affected Plugin
- Social Media Widget
- Affected Version
4.0- CVSS
- 5.3Medium
- Weakness type
- CWE-610 · Externally Controlled Reference to a Resource in Another Sphere
- CVE
CVE pending
At a glance
This record tracks a medium-severity Externally Controlled Reference to a Resource in Another Sphere vulnerability in the Social Media Widget WordPress plugin, affecting versions 4.0. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 4.0.1; sites on affected versions should update now. Disclosed April 2013, reported by DANIEL CID.
Vulnerability Overview
The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-610: Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Remediation
Update to version 4.0.1, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Social Media Widget 4.0.1 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Social Media Widget
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C