Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites
ID: d970b9e7-c1d1-58dc-af3e-f71c9d63ff2e
STIX ID: report--d970b9e7-c1d1-58dc-af3e-f71c9d63ff2e
Feed Name: TechCrunch Security News
A supply-chain backdoor was discovered in dozens of WordPress plugins from a vendor called Essential Plugin after the plugins changed ownership; the backdoor, dormant for months, activated and began distributing malicious code to sites that had the plugins installed. WordPress lists the affected plugins in over 20,000 active installations (the vendor claims up to 400,000 installs); the plugins have been removed from the directory and site owners are advised to check for and remove the compromised plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
