Social Media Widget 4.0 - Spam Link Injection

2013-04-09 00:00
DANIEL CID

Strategic Overview

Status
Patched in 4.0.1
Affected PluginSocial Media Widget
Affected Version4.0
CVSS5.3Medium
CVEN/A
View all Social Media Widget vulnerabilities

Vulnerability Overview

The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.

Technical Analysis

REMEDIATION: Update to version 4.0.1, or a newer patched version --- IDENTIFIER: CWE-610 (Externally Controlled Reference to a Resource in Another Sphere) The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C