Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin Social Media Widget Serving Spam (4.0) - Vulnerability Database

WordPress Plugin Social Media Widget Serving Spam (4.0)

Description

WordPress Plugin Social Media Widget has a hidden call to i.aaur.net/i.php, which is used to inject Pay Day Loan spam into the web sites running the plugin. WordPress Plugin Social Media Widget version 4.0 is vulnerable; other versions may also be affected.

Remediation

Update to plugin version 4.0.2 or latest