Website Defender, a company specialising in website security, reported security vulnerability in one of the very popular plugins – Social Media Widget.
If you are using the Social Media Widget plugin, make sure to remove it immediately from your website. The plugin is being used to inject not only spam into websites, but also malicious code.
This is a very popular plugin with more than 900,000 downloads. It has the potential to impact a lot of websites. The plugin has a hidden call to this URL: httx://i.aaur.net/i.php, which is used to inject “Pay Day Loan” spam into the web sites running the plugin. Continue reading