WordPress Plugin Hacked Since 2020 to Inject Malicious Code Silently
ID: ab7f3ddc-f37b-51d8-a0da-fe8e1b3ba579
STIX ID: report--ab7f3ddc-f37b-51d8-a0da-fe8e1b3ba579
Feed Name: cybersecurityNews.com
A supply-chain compromise was discovered in the Quick Page/Post Redirect WordPress plugin (reported in version 5.2.3) where the plugin author introduced a malicious self-updater in 2020 and later deployed a backdoor that injected hidden content and enabled remote code execution and parasite SEO across tens of thousands of sites; while the C2 is currently offline the update mechanism remains functional and administrators are advised to verify plugin checksums and remove the compromised plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
