logo

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites

ID: 4ffa9fd2-3d13-536a-baff-570b807fa9ad

STIX ID: report--4ffa9fd2-3d13-536a-baff-570b807fa9ad

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-14

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Researchers at c/side discovered a malware campaign leveraging the wp3.xyz domain that has compromised more than 5,000 WordPress sites by creating a hard-coded rogue admin account (wpx_admin), installing and activating a malicious plugin (plugin.php), and exfiltrating administrator credentials and logs via obfuscated requests that mimic image traffic; site owners are advised to block wp3.xyz, review privileges and plugins, strengthen CSRF protections, and implement MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.