logo

Backdoored WordPress Plugin Abuses Remote Update Checker for Silent Code Delivery

ID: 6e508d52-448e-5ae7-9481-f5631680c1c8

STIX ID: report--6e508d52-448e-5ae7-9481-f5631680c1c8

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

A stealthy supply-chain compromise was discovered in the Quick Page/Post Redirect Plugin (v5.2.3): the plugin contained a custom updater pointing to anadnet.com that allowed the attacker to push backdoored updates (RCE) and insert hidden content for logged-out visitors (parasite SEO). The malicious code matched the official version number, evaded scanners, persisted across ~70,000 active installations for over five years, and site owners are advised to verify plugin checksums via WP-CLI and uninstall the compromised plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.