Trusted WordPress Plugins Weaponized In Delayed Malware Campaign
ID: ea4b8a72-5cdd-58ac-9873-eb3b9cf6c470
STIX ID: report--ea4b8a72-5cdd-58ac-9873-eb3b9cf6c470
Feed Name: Cyber Press
Trusted WordPress plugins in the Essential Plugin portfolio were weaponized after a commercial acquisition: a PHP deserialization backdoor and an unauthenticated REST API were introduced in an update (v2.6.7, Aug 8, 2025) and left dormant until April 5–6, 2026, when analytics.essentialplugin.com distributed malicious payloads that enabled remote code execution, SEO spam, and backdoor access across many sites. The incident demonstrates a large-scale supply-chain attack enabled by post-sale code changes, lack of change-of-control processes on WordPress.org, and propagation through normal auto-update channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
