Social Media Widget [social-media-widget] < 4.0.9
unknown
[en] The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Jul 12, 2024
CVE-2024-0974 on NVD →
Social Media Widget <= 4.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Social Media Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "VK URL" field in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to injec...
- CVSS:
- 4.4
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.9
- Disclosed:
- Jun 21, 2024
CVE-2024-0974 on NVD →
Social Media Widget [social-media-widget] < 2.3
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Aug 21, 2015
Social Media Widget [social-media-widget] < 4.0.2
unknown
This plugin is prone to an unspecified issue, because of malicious code.
Update the plugin.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- May 15, 2015
Social Media Widget [social-media-widget] < 4.0.1
unknown
[en] Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Apr 25, 2013
CVE-2013-1949 on NVD →
Social Media Widget 4.0 - Spam Link Injection
medium
The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.
- CVSS:
- 5.3
- Affected:
- 4.0 – 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Apr 9, 2013
Social Media Widget [social-media-widget] < 4.0.1
unknown
The Social Media Widget plugin for WordPress is vulnerable to Spam Link Injection in version 4.0. This is due to a hidden call to an external link which makes it possible for spam to be injected into the affected site.
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Apr 9, 2013
Social Media Widget <= 4.0 - Arbitrary File Upload
critical
Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.
- CVSS:
- 9.8
- Affected:
- up to 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Apr 8, 2013
CVE-2013-1949 on NVD →
Social Media Widget [social-media-widget] < 1.0.8
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML via the "id" parameter.
Update the plugin.
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Feb 19, 2013
Social Media Widget [social-media-widget] < 4.0.2
unknown
The Social Media Widget WordPress plugin was affected by a Malicious Code security vulnerability.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database