Targeting Multiple Vulnerable WordPress Plugins
ID: e5aeca47-ca19-5bab-92e2-99e3e2021243
STIX ID: report--e5aeca47-ca19-5bab-92e2-99e3e2021243
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive Summary:** Zscaler ThreatLabZ discovered active campaigns exploiting three patched WordPress plugin vulnerabilities (outdated WooCommerce, Yoast SEO, and All in One SEO Pack) to inject obfuscated redirector JavaScript into many sites; victims are redirected through an IP (134.249.116.78) and scam pages that lead to adult sites or a spoofed Microsoft phishing page for credential theft, with a sizable list of compromised domains and IoCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
