logo

OptinMonster Plugin Flaw Exposes 1.2 Million WordPress Sites to Attacks

ID: b0135cae-85ee-55d2-8c63-68528ea284e7

STIX ID: report--b0135cae-85ee-55d2-8c63-68528ea284e7

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Lucas Martin

...
...

A sophisticated supply-chain attack tampered with CDN-hosted JavaScript for OptinMonster, TrustPulse, and PushEngage, exposing around 1.2 million WordPress sites; the payload targeted logged-in administrators to harvest REST/AJAX nonces, create rogue admin accounts (e.g., developer_api1 and dev_xxxxxx), and silently install a self-hiding PHP backdoor plugin (disguised as Content Delivery Helper/Database Optimizer) that provides unauthenticated shell and eval endpoints. Sansec confirmed injections on June 12–14, 2026 and Awesome Motive traced the root cause to an UpdraftPlus vulnerability and a leaked CDN API key; the report lists multiple IOCs including the C2 domain tidio.cc, C2 endpoints, an XOR key, plugin names, and observed account-creation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.