Threat Intelligence: WordPress Zero-day
ID: f812c51a-3363-54da-8798-4a13c86ef50f
STIX ID: report--f812c51a-3363-54da-8798-4a13c86ef50f
Feed Name: Binary Defense Blog
A zero-day in the WP GDPR Compliance WordPress plugin (affecting versions 1.4.2 and older) is being actively exploited to force changes to plugin/CMS settings, enable public registration, create administrative accounts (e.g., "t2trollherten"), enqueue malicious WP-Cron tasks, and install backdoors (notably files named "wp-cache.php" or "wp-cahe.php"). The plugin was removed and later updated to v1.4.3 to patch the issue; site owners should update immediately and inspect for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
