WordPress Vulnerability Report: Supply Chain Compromise in EssentialPlugin
A serious security vulnerability has been identified in multiple WordPress plugins developed by EssentialPlugin. Following the acquisition of the company, a malicious actor embedded a backdoor in over 20 plugins, allowing them to distribute malware to thousands of WordPress sites.
Vulnerability Explanation: This incident, known as a supply chain compromise, occurred when the new owner activated a dormant backdoor disguised as a routine update. This backdoor could execute commands and write arbitrary files on affected sites.
Affected Component: The compromised plugins include popular options like WP Logo Showcase and Countdown Timer.
Impact: If left unaddressed, these vulnerabilities could lead to complete site compromise.
Fix: Users should immediately update their plugins to the latest versions. The WordPress Plugin Review team has removed the affected plugins and implemented security measures.
Risk Level: High. Site administrators are urged to act swiftly to protect their sites.
Source: View Original Report
