WordPress Supply Chain Attack Spreads Across Multiple Plug-ins
ID: 154f6a60-db12-584c-bd36-2c81932893fd
STIX ID: report--154f6a60-db12-584c-bd36-2c81932893fd
Feed Name: Dark Reading
Date Published: 2024-06-25
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Wordfence discovered a supply-chain attack that injected malicious code into multiple WordPress.org plugins (notably Social Warfare with >30,000 installs) that creates unauthorized administrative accounts, injects malicious JavaScript and SEO spam, and exfiltrates credentials to an attacker-controlled server (94.156.79.8); affected plugins have been delisted, some patched, and Wordfence published IoCs and cleanup guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
