logo

Popular WordPress redirect plugin hid dormant backdoor for years

ID: 8f2020a4-5cb4-5d76-9433-7afa6e4366ed

STIX ID: report--8f2020a4-5cb4-5d76-9433-7afa6e4366ed

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Bill Toulas

...
...

A hidden self-update mechanism shipped in Quick Page/Post Redirect plugin versions 5.2.1/5.2.2 routed update checks to an external domain (anadnet.com), enabling a tampered 5.2.3 build to be silently delivered that included a passive backdoor (triggering for logged-out users) likely used for SEO spam; the updater could also allow arbitrary remote code execution. WordPress.org removed the malicious updater and pulled the plugin pending review, but about 70,000 installs may still point to the malicious update server and remain at risk; affected users are advised to uninstall and reinstall a clean 5.2.4 from WordPress.org when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.