logo

Nearly 7K WordPress Sites Compromised by Balada Injector

ID: 83edeede-1296-5606-bbbc-1d5690288eda

STIX ID: report--83edeede-1296-5606-bbbc-1d5690288eda

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-17

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

About 6,700 WordPress sites were infected by the long-running Balada Injector campaign after attackers exploited an XSS vulnerability (CVE-2023-6000) in the Popup Builder plugin to inject malicious JavaScript and a backdoor into wp-blog-header.php, redirecting visitors to scam or compromised pages; the vulnerable plugin has ~200,000 installations and the campaign has historically compromised over one million sites, with recommended mitigations including integrity monitoring, minimizing third-party code, and regular updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.