WordPress , and specifically its plugins, have been the target of attacks. This has happened again now as a vulnerability was discovered in the WordPress plugin, Social Warfare, the exploitation of which resulted in the removal of the plugin from WordPress.
Social Warfare is quite popular as it allows users to place social media sharing buttons on their websites.
Social Warfare's install base includes over 70,000 sites and over 805,000 downloads.
However, researchers discovered that the latest version of the plugin is affected by a cross-site scripting vulnerability, which is already being exploited by hackers.
According to Mikey Veenstra and Wordfence, this vulnerability allows the insertion of malicious JavaScript code into shared links.
It appears that the attacks began after the vulnerability by a security researcher, whose identity is unknown.
This resulted in the plugin being removed. On the WordPress page , searching for Social Warfare showed the message: “This plugin was discontinued on March 21, 2019 and is no longer available for download.”
Social Warfare announced that it is aware of the vulnerability and is working to fix the issue by creating a patch. It also suggested that users disable the plugin until an updated version is released.
For now, Wordfence will not disclose further details about the attacks and the vulnerability. More information will be available when the issue is addressed. Not long ago, another WordPress plugin, Easy WP SMTP, was affected by a vulnerability, which hackers in order to gain administrative control of the sites affected by the vulnerability. However, it was fixed via a patch.
"Attacks through this vulnerability are widespread, and successful exploits can give attackers complete control of vulnerable sites ," Veestra said
