Major WordPress Plugin Hack: Malware Hits Thousands of Sites

Date:

Malware Attack Targets Popular WordPress Plugins, Compromising Thousands of Sites

A significant cybersecurity incident has emerged as more than 30 plugins from the EssentialPlugin package for WordPress have been compromised with malicious code. This attack, which began last year but recently escalated, grants unauthorized access to websites using these plugins, affecting hundreds of thousands of active installations.

The attacker introduced a backdoor, enabling the retrieval of spam links and redirects while remaining undetected by site owners. The malicious activity was discovered by Austin Ginder, founder of Anchor Hosting, after receiving a tip-off regarding suspicious code in one plugin.

Although WordPress.org has acted swiftly to disable the compromised plugins and push updates, concerns remain as the malware can still lurk in other files, particularly affecting the wp-config.php file.

Website administrators are urged to review their installations and ensure all files are clean.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...