Social Media Widget 4.0 - Spam Link Injection
2013-04-09 00:00
DANIEL CIDStrategic Overview
Vulnerability Overview
The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.
Technical Analysis
REMEDIATION: Update to version 4.0.1, or a newer patched version --- IDENTIFIER: CWE-610 (Externally Controlled Reference to a Resource in Another Sphere) The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C