{"id":1572,"date":"2013-04-11T13:05:00","date_gmt":"2013-04-11T13:05:00","guid":{"rendered":"http:\/\/xislblogs.xtreamlab.net\/slwoods\/?p=1572"},"modified":"2013-04-11T13:08:49","modified_gmt":"2013-04-11T13:08:49","slug":"wordpress-plugin-social-media-widget-hiding-spam","status":"publish","type":"post","link":"https:\/\/www.slwoods.co.uk\/?p=1572","title":{"rendered":"WordPress Social Media widget hiding spam"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.slwoods.co.uk\/wp-content\/uploads\/sites\/23\/2013\/04\/WordPress_logo.png\" alt=\"WordPress logo\" width=\"200\" height=\"46\" class=\"alignright size-full wp-image-1574\" \/>Two days ago, the <a href=\"http:\/\/blog.sucuri.net\/2013\/04\/wordpress-plugin-social-media-widget.html\">Sicuri Blog reported<\/a> a serious security problem with the Social Media widget for <a href=\"http:\/\/wordpress.org\/\">WordPress<\/a>, one of the world&#8217;s most popular open source blogging platforms.<\/p>\n<p>To quote:<\/p>\n<blockquote><p>If you are using the Social Media Widget plugin (social-media-widget), make sure to remove it immediately from your website. We discovered it is being used to inject spam into websites and it has also been removed from the <a href=\"http:\/\/wordpress.org\/extend\/plugins\/\">WordPress Plugin repository<\/a>.<\/p>\n<p>This is a very popular plugin with more than 900,000 downloads. It has the potential to impact a lot of websites.<\/p>\n<p>The plugin has a hidden call to this URL: httx:\/\/i.aaur.net\/i.php, which is used to inject \u201cPay Day Loan\u201d spam into the web sites running the plugin.<\/p><\/blockquote>\n<p>The authors report that the malicious code was added only 12 days ago when version 4.0 of the plug-in was released and <a href=\"http:\/\/www.h-online.com\/open\/news\/item\/Social-Media-Widget-for-WordPress-a-source-of-spam-1838405.html\">The H Online IT news site reports<\/a> that the package had a change of maintainers back in January this year.<\/p>\n<p>Besides removing this particular widget, users are advised to find another plug-in to replace it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two days ago, the Sicuri Blog reported a serious security problem with the Social Media widget for WordPress, one of the world&#8217;s most popular open source blogging platforms. To quote: If you are using the Social Media Widget plugin (social-media-widget), make sure to remove it immediately from your website. We discovered it is being used [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,9],"tags":[12,23],"class_list":["post-1572","post","type-post","status-publish","format-standard","hentry","category-open-source-software","category-tech","tag-open-source","tag-tech-2"],"_links":{"self":[{"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1572"}],"version-history":[{"count":6,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1572\/revisions"}],"predecessor-version":[{"id":1577,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/1572\/revisions\/1577"}],"wp:attachment":[{"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.slwoods.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}