Malicious JavaScript in WordPress Plugins
ID: 61e6b1dd-3038-5c15-adc8-51ce0ca9df70
STIX ID: report--61e6b1dd-3038-5c15-adc8-51ce0ca9df70
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes active exploitation of a pre-auth stored XSS in the WordPress Live Chat Support plugin (patched in v8.0.27) where attackers inject obfuscated JavaScript that loads a payload from blackawardago.com (IP 216.10.243.93) to perform malicious redirects, pop-ups and fake subscription prompts; a pastebin list of compromised sites and related IOCs are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
