logo

WordPress Supply Chain Attack Spreads Across Multiple Plug-ins

ID: 154f6a60-db12-584c-bd36-2c81932893fd

STIX ID: report--154f6a60-db12-584c-bd36-2c81932893fd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-25

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Wordfence discovered a supply-chain attack that injected malicious code into multiple WordPress.org plugins (notably Social Warfare with >30,000 installs) that creates unauthorized administrative accounts, injects malicious JavaScript and SEO spam, and exfiltrates credentials to an attacker-controlled server (94.156.79.8); affected plugins have been delisted, some patched, and Wordfence published IoCs and cleanup guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.