logo

Backdoored WordPress Plugin Uses Remote Update for Code Delivery

ID: 8b30ccec-ebe2-5904-b073-b4d3ca5dd8c6

STIX ID: report--8b30ccec-ebe2-5904-b073-b4d3ca5dd8c6

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

A tampered Quick Page/Post Redirect WordPress plugin (v5.2.3) contained a passive content-injection hook that served backlinks to logged-out visitors and an active backdoor that registered an external update server (anadnet.com) allowing remote arbitrary plugin updates; researcher analysis, SVN commits, and an Internet Archive snapshot confirm the compromise, and administrators are advised to uninstall the plugin and replace it with alternatives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.