logo

Creepy Crawlers: Hunting Those Who Hunt For WordPress Plugins

ID: 24c5c32f-7d78-58a7-88a2-9f4c4b79e89e

STIX ID: report--24c5c32f-7d78-58a7-88a2-9f4c4b79e89e

Feed Name: GreyNoise Labs

Threat Score
65/100

Date Published: 2026-01-19

Date Updated: 2026-04-27

Author: hrbrmstr + 🔮Orbie✨

...
...

GreyNoise observed ~40K unique WordPress plugin enumeration events over 92 days, revealing coordinated and persistent scanning from multiple ASNs (notably UCLOUD HK, Akamai/Linode) including 91 single-plugin specialists focused on the post-smtp plugin, a large Sri Lanka Telecom-driven spike scanning 334 plugins in two days, and weekend-biased automated scanning; the report ties scanning activity to published CVEs for targeted plugins (e.g., post-smtp account-takeover CVE) and recommends tagging, JA4-based alerting, weekend monitoring, and patching high-risk plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.