logo

Trusted WordPress Plugins Weaponized In Delayed Malware Campaign

ID: ea4b8a72-5cdd-58ac-9873-eb3b9cf6c470

STIX ID: report--ea4b8a72-5cdd-58ac-9873-eb3b9cf6c470

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-15

Date Updated: 2026-04-19

Author: Varshini

...
...

Trusted WordPress plugins in the Essential Plugin portfolio were weaponized after a commercial acquisition: a PHP deserialization backdoor and an unauthenticated REST API were introduced in an update (v2.6.7, Aug 8, 2025) and left dormant until April 5–6, 2026, when analytics.essentialplugin.com distributed malicious payloads that enabled remote code execution, SEO spam, and backdoor access across many sites. The incident demonstrates a large-scale supply-chain attack enabled by post-sale code changes, lack of change-of-control processes on WordPress.org, and propagation through normal auto-update channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.