logo

New Balada Injector campaign infects 6,700 WordPress sites

ID: 23fee68a-886f-5c7d-8a92-1af89810cfaf

STIX ID: report--23fee68a-886f-5c7d-8a92-1af89810cfaf

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A mid-December Balada Injector campaign exploited a stored XSS in the Popup Builder WordPress plugin (CVE-2023-6000) to inject malicious JavaScript into site databases and modify core files, then deploy a PHP backdoor ('wp-felody.php') that enables arbitrary code execution, file uploads, and retrieval of additional payloads; the campaign has compromised thousands of sites (approximately 6,700 in the latest wave, and reported historical totals >17,000), redirecting visitors to scam pages and push-notification fraud — site owners should update or remove vulnerable plugins and minimize active plugins to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.