logo

Targeting Multiple Vulnerable WordPress Plugins

ID: e5aeca47-ca19-5bab-92e2-99e3e2021243

STIX ID: report--e5aeca47-ca19-5bab-92e2-99e3e2021243

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabZ discovered active campaigns exploiting three patched WordPress plugin vulnerabilities (outdated WooCommerce, Yoast SEO, and All in One SEO Pack) to inject obfuscated redirector JavaScript into many sites; victims are redirected through an IP (134.249.116.78) and scam pages that lead to adult sites or a spoofed Microsoft phishing page for credential theft, with a sizable list of compromised domains and IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.