logo

Plugins on WordPress.org backdoored in supply chain attack

ID: dbfbaf2d-fcc0-50c4-ac96-9a18dec13257

STIX ID: report--dbfbaf2d-fcc0-50c4-ac96-9a18dec13257

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A supply-chain compromise on WordPress.org resulted in malicious PHP injections into five plugins that create admin accounts (notably named “Options” and “PluginAuth”), inject SEO spam, and send data to IP 94.156.79.8; the modifications affected plugins installed on over 35,000 sites and most have since received patches after discovery by Wordfence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.