Deactivate The Social Warfare Plugin ASAP!

blog cover image
65
77
3.1K followers

This is a very short post but it has important information about a security issue. About one hour ago information was published about earlier today hackers injected malicious code into the popular WordPress Plugin Social Warfare. If you installed this plugin, deactivate it ASAP. Otherwise, your site will be taken to malicious sites. KEEP IT DEACTIVATED until a patch is released.

65
77

Join FREE & Launch Your Business!

Exclusive Bonus - Offer Ends at Midnight Today

00

Hours

:

00

Minutes

:

00

Seconds

2,000 AI Credits Worth $10 USD

Build a Logo + Website That Attracts Customers

400 Credits

Discover Hot Niches with AI Market Research

100 Credits

Create SEO Content That Ranks & Converts

800 Credits

Find Affiliate Offers Up to $500/Sale

10 Credits

Access a Community of 2.9M+ Members

By continuing, you agree to our Terms of Service and Privacy Policy
No credit card required

Recent Comments

77

Where can this be verified? I can't find any info about this security breach anywhere.

From WordFence (about two hours ago):

“Earlier today, an unnamed security researcher published a full disclosure of a stored Cross-Site Scripting (XSS) vulnerability present in the most recent version of popular WordPress plugin Social Warfare. The plugin, which was subsequently removed from the http://WordPress.org plugin repository, has an active install base of over 70,000 sites. The flaw allows attackers to inject malicious JavaScript code into the social share links present on a site’s posts, and is under active attack in the wild.

We've just published a brief PSA including recommendations for impacted site owners.”

https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/

1

Thanks so much!

1

You’re welcome!
Tom

Oh wow! This explains it!!! Oh My goodness. Been on with site support all day. Off to deactivate it now. Thanks so much

1

You’re welcome!
Tom

Thanks for this information

1

You’re welcome!
Tom

1

Good to know, thanks. What is the plugin supposed to do?

1

It’s a social sharing plugin.

1

OK thanks.

Thank you for the advice.

1

You’re welcome!
Tom

1

Thank you!

1

You’re welcome!
Tom

Thanks!

1

You’re welcome!
Tom

Glad you let us know.

1

You’re welcome!
Tom

1

Boy glad I haven't done that yet. I am still recovering from a Russian hack to my computer. Scared the ....... out of me. But it was verified through google. 30 days plus without my computer, needed to wipe it clean, and reinstall all my programs, and had to add a strong firewall.

This is getting pretty scary.
Have to keep a watchful eye.

Thanks for the heads up :)

1

You’re welcome!
Tom

See more comments

Join FREE & Launch Your Business!

Exclusive Bonus - Offer Ends at Midnight Today

00

Hours

:

00

Minutes

:

00

Seconds

2,000 AI Credits Worth $10 USD

Build a Logo + Website That Attracts Customers

400 Credits

Discover Hot Niches with AI Market Research

100 Credits

Create SEO Content That Ranks & Converts

800 Credits

Find Affiliate Offers Up to $500/Sale

10 Credits

Access a Community of 2.9M+ Members

By continuing, you agree to our Terms of Service and Privacy Policy
No credit card required

2.9M+

Members

190+

Countries Served

20+

Years Online

50K+

Success Stories

The world's most successful affiliate marketing training platform. Join 2.9M+ entrepreneurs building their online business with expert training, tools, and support.

© 2005-2025 Wealthy Affiliate
All rights reserved worldwide.

🔒 Trusted by Millions Worldwide

Since 2005, Wealthy Affiliate has been the go-to platform for entrepreneurs looking to build successful online businesses. With industry-leading security, 99.9% uptime, and a proven track record of success, you're in safe hands.