logo

Malicious JavaScript in WordPress Plugins

ID: 61e6b1dd-3038-5c15-adc8-51ce0ca9df70

STIX ID: report--61e6b1dd-3038-5c15-adc8-51ce0ca9df70

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes active exploitation of a pre-auth stored XSS in the WordPress Live Chat Support plugin (patched in v8.0.27) where attackers inject obfuscated JavaScript that loads a payload from blackawardago.com (IP 216.10.243.93) to perform malicious redirects, pop-ups and fake subscription prompts; a pastebin list of compromised sites and related IOCs are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.