Nearly 7K WordPress Sites Compromised by Balada Injector
ID: 83edeede-1296-5606-bbbc-1d5690288eda
STIX ID: report--83edeede-1296-5606-bbbc-1d5690288eda
Feed Name: Dark Reading
About 6,700 WordPress sites were infected by the long-running Balada Injector campaign after attackers exploited an XSS vulnerability (CVE-2023-6000) in the Popup Builder plugin to inject malicious JavaScript and a backdoor into wp-blog-header.php, redirecting visitors to scam or compromised pages; the vulnerable plugin has ~200,000 installations and the campaign has historically compromised over one million sites, with recommended mitigations including integrity monitoring, minimizing third-party code, and regular updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
