CVE-2013-1949: Blinkwebeffects Social-Media-Widget

Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.

Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.

Affected products

Published 2013-04-25. Last modified 2026-06-16.