logo

Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites

ID: 6e8b7a2a-682c-52cc-9ec8-37b1f8186953

STIX ID: report--6e8b7a2a-682c-52cc-9ec8-37b1f8186953

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A malware campaign is actively exploiting a high-severity stored XSS/privilege escalation vulnerability in the Popup Builder WordPress plugin (CVE-2023-6000) to inject malicious JavaScript that redirects visitors to phishing and scam pages and can lead to creation of rogue admin users and arbitrary plugin installation; Sucuri reports over ~3,900 infected sites in three weeks. The report also highlights recently patched high-severity flaws in other WordPress components (Ultimate Member CVE-2024-2123 and Avada CVE-2024-1468) and urges plugin/theme updates and site scans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.