Backdoored WordPress Plugin Uses Remote Update for Code Delivery
ID: 8b30ccec-ebe2-5904-b073-b4d3ca5dd8c6
STIX ID: report--8b30ccec-ebe2-5904-b073-b4d3ca5dd8c6
Feed Name: Cyber Press
Threat Score
A tampered Quick Page/Post Redirect WordPress plugin (v5.2.3) contained a passive content-injection hook that served backlinks to logged-out visitors and an active backdoor that registered an external update server (anadnet.com) allowing remote arbitrary plugin updates; researcher analysis, SVN commits, and an Internet Archive snapshot confirm the compromise, and administrators are advised to uninstall the plugin and replace it with alternatives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
