Description
WordPress Plugin Social Media Widget has a hidden call to i.aaur.net/i.php, which is used to inject Pay Day Loan spam into the web sites running the plugin. WordPress Plugin Social Media Widget version 4.0 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 4.0.2 or latest
References
https://blog.sucuri.net/2013/04/wordpress-plugin-social-media-widget.html
http://www.openwall.com/lists/oss-security/2013/04/14/1
https://wordpress.org/plugins/social-media-widget/changelog/
Related Vulnerabilities
PHP error logging format string vulnerability
WordPress Plugin WooCommerce PayPal Checkout Payment Gateway Parameter Tampering (1.6.8)
Oracle Database Server CVE-2006-5336 Vulnerability (CVE-2006-5336)
WordPress Plugin WooCommerce Admin Security Bypass (2.6.3)
Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-6188)