Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Stylized illustration a door that opens onto a wall of computer code.

Enlarge (credit: Getty Images)

reported. Over the past week, unknown threat actors have added malicious functions to updates available for the plugins on, the official site for the open source WordPress CMS software. When installed, the updates automatically create an attacker-controlled administrative account that provides full control over the compromised site. The updates also add content designed to goose search results.

Poisoning the well

“The injected malicious code is not very sophisticated or heavily obfuscated and contains comments throughout making it easy to follow,” the researchers wrote. “The earliest injection appears to date back to June 21st, 2024, and the threat actor was still actively making updates to plugins as recently as 5 hours ago.”

Read 6 remaining paragraphs | Comments

Article Tags:
Article Categories: