Description
WordPress Plugin Social Media Widget has a hidden call to i.aaur.net/i.php, which is used to inject Pay Day Loan spam into the web sites running the plugin. WordPress Plugin Social Media Widget version 4.0 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 4.0.2 or latest
References
https://blog.sucuri.net/2013/04/wordpress-plugin-social-media-widget.html
http://www.openwall.com/lists/oss-security/2013/04/14/1
https://wordpress.org/plugins/social-media-widget/changelog/
Related Vulnerabilities
MySQL CVE-2019-2502 Vulnerability (CVE-2019-2502)
ownCloud Incorrect Authorization Vulnerability (CVE-2021-35949)
Jboss EAP Missing Authorization Vulnerability (CVE-2019-10184)
GeoServer CVE-2023-35042 Vulnerability (CVE-2023-35042)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2014-0118)