logo

Researchers Uncover Active Exploitation of WordPress Plugin Vulnerabilities

ID: 47ed4dc3-933d-5332-88f7-1c3fad2e23d3

STIX ID: report--47ed4dc3-933d-5332-88f7-1c3fad2e23d3

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-30

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers warn that multiple high-severity unauthenticated stored XSS vulnerabilities in WordPress plugins (including CVE-2023-6961, CVE-2023-40000, CVE-2024-2194) are being actively exploited to inject obfuscated JavaScript that creates rogue admin accounts, implants PHP backdoors into plugins/themes, and contacts a remote tracking domain (ur.mystiqueapi.com). Fastly observed exploitation traffic tied to AS202425 and WPScan previously reported similar abuse; site owners are advised to update plugins, audit for malicious admins/backdoors, and remove compromised code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.