logo

WordPress plugin suite hacked to push malware to thousands of sites

ID: fab6ddc4-1a5e-550d-9e81-42a6d957e90f

STIX ID: report--fab6ddc4-1a5e-550d-9e81-42a6d957e90f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

More than 30 WordPress plugins in the EssentialPlugin package were compromised after an acquisition, with a backdoor present since August 2025 that was recently activated to fetch and inject malware (via a downloaded `wp-comments-posts.php` payload that modifies `wp-config.php`). The malware uses Ethereum-based C2 address resolution, selectively serves spam/redirects to Googlebot, and affected plugins have hundreds of thousands of active installations; WordPress.org forced updates to disable communication but warned infected `wp-config.php` files may remain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.