Social Media Widget 4.0 - Spam Link Injection

2013-04-09 00:00
DANIEL CID

Strategic Overview

Status
Patched in 4.0.1
Affected Plugin
Social Media Widget
Affected Version
4.0
CVSS
5.3Medium
Weakness type
CWE-610 · Externally Controlled Reference to a Resource in Another Sphere
CVE
CVE pending
View all Social Media Widget vulnerabilities

At a glance

This record tracks a medium-severity Externally Controlled Reference to a Resource in Another Sphere vulnerability in the Social Media Widget WordPress plugin, affecting versions 4.0. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 4.0.1; sites on affected versions should update now. Disclosed April 2013, reported by DANIEL CID.

Vulnerability Overview

The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.

CWE-610: Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Remediation

Update to version 4.0.1, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Social Media Widget 4.0.1 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C