logo

Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

ID: 1a40a00d-a952-59ee-a00d-e2d374aae278

STIX ID: report--1a40a00d-a952-59ee-a00d-e2d374aae278

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-25

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Multiple WordPress plugins were backdoored in a supply-chain campaign (earliest signs June 21, 2024) that injects code to create rogue admin accounts (usernames “Options” and “PluginAuth”), exfiltrates those credentials to 94.156.79.8, and inserts malicious JavaScript for SEO spam; affected plugins have been removed from the directory and site owners are advised to remove suspicious admin accounts and malicious code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.