PhishWP Plug-in Hijacks WordPress E-Commerce Checkouts
ID: f7e94aa8-962a-598f-9448-e32a7f11e382
STIX ID: report--f7e94aa8-962a-598f-9448-e32a7f11e382
Feed Name: Dark Reading
Date Published: 2025-01-07
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SlashNext researchers report a malicious WordPress plug-in called PhishWP that creates highly convincing fake checkout flows on compromised or fraudulent WordPress sites to steal credit card data, billing information, one-time passwords, and browser/profile metadata; stolen data is immediately exfiltrated to attackers via Telegram, and the plug-in includes obfuscation, multilanguage support, auto-response confirmations, and customization to facilitate broad, fast fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
