logo

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

ID: d970b9e7-c1d1-58dc-af3e-f71c9d63ff2e

STIX ID: report--d970b9e7-c1d1-58dc-af3e-f71c9d63ff2e

Feed Name: TechCrunch Security News

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

A supply-chain backdoor was discovered in dozens of WordPress plugins from a vendor called Essential Plugin after the plugins changed ownership; the backdoor, dormant for months, activated and began distributing malicious code to sites that had the plugins installed. WordPress lists the affected plugins in over 20,000 active installations (the vendor claims up to 400,000 installs); the plugins have been removed from the directory and site owners are advised to check for and remove the compromised plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.