Major WordPress Plugin Hack: Malware Hits Thousands of Sites

Date:

Malware Attack Targets Popular WordPress Plugins, Compromising Thousands of Sites

A significant cybersecurity incident has emerged as more than 30 plugins from the EssentialPlugin package for WordPress have been compromised with malicious code. This attack, which began last year but recently escalated, grants unauthorized access to websites using these plugins, affecting hundreds of thousands of active installations.

The attacker introduced a backdoor, enabling the retrieval of spam links and redirects while remaining undetected by site owners. The malicious activity was discovered by Austin Ginder, founder of Anchor Hosting, after receiving a tip-off regarding suspicious code in one plugin.

Although WordPress.org has acted swiftly to disable the compromised plugins and push updates, concerns remain as the malware can still lurk in other files, particularly affecting the wp-config.php file.

Website administrators are urged to review their installations and ensure all files are clean.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...