logo

WP Automatic WordPress plugin hit by millions of SQL injection attacks

ID: 44a7c301-86bf-5ccb-9b2f-f7e78b7a23d3

STIX ID: report--44a7c301-86bf-5ccb-9b2f-f7e78b7a23d3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-04-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical SQL injection vulnerability (CVE-2024-27956, CVSS 9.9) in the WP Automatic WordPress plugin (pre-3.9.2.0) is being actively exploited to create admin accounts and deploy backdoors; Automattic's WPScan observed over 5.5 million attack attempts and provides IOCs (e.g., admin accounts starting with "xtw", files named web.php and index.php, and renamed csv.php). Site owners should update the plugin to 3.92.1 or later, check for the listed IOCs, and restore from clean backups if compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.