Description
WordPress Plugin Social Sharing-Social Warfare contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Social Sharing-Social Warfare versions 4.4.6.4 - 4.4.7.1 are affected.
Remediation
Update to plugin version 4.4.7.3 or latest
References
https://wordpress.org/support/topic/a-security-message-from-the-plugin-review-team/
https://plugins.svn.wordpress.org/social-warfare/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin EMC2 Custom Help Videos Cross-Site Scripting (1.2)
WordPress Plugin Woo Email Control Cross-Site Scripting (1.01)
WordPress Plugin Migration, Backup, Staging-WPvivid Security Bypass (0.9.35)
WordPress Plugin Affiliates Manager Cross-Site Scripting (2.8.9)
WordPress Plugin Check & Log Email Cross-Site Scripting (0.5.1)