logo

Malicious WordPress Plugins with Backdoors Compromise Thousands of Websites

ID: c0240f99-78d4-590f-bd68-7e50c8024cf1

STIX ID: report--c0240f99-78d4-590f-bd68-7e50c8024cf1

Feed Name: TechRepublic Security

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

A threat actor bought the Essential Plugin portfolio, implanted dormant backdoors into 31 WordPress plugins (including a plugin with ~20k installs), and used an Ethereum smart contract to resolve and persistently update C2 servers; WordPress has removed the plugins and site owners are advised to delete or patch affected plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.