Description
WordPress Plugin Social Media Widget has a hidden call to i.aaur.net/i.php, which is used to inject Pay Day Loan spam into the web sites running the plugin. WordPress Plugin Social Media Widget version 4.0 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 4.0.2 or latest
References
https://blog.sucuri.net/2013/04/wordpress-plugin-social-media-widget.html
http://www.openwall.com/lists/oss-security/2013/04/14/1
https://wordpress.org/plugins/social-media-widget/changelog/
Related Vulnerabilities
WordPress Plugin Responsive Poll Security Bypass (1.3.4)
Drupal Core 8.7.4 Security Bypass (8.7.4)
WordPress Plugin Xhanch-My Twitter Multiple Cross-Site Request Forgery Vulnerabilities (2.7.7)
WordPress Plugin LazyEater Unspecified Vulnerability (1.2.1)
Oracle Application Server Other Vulnerability (CVE-2005-3204)