logo

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

ID: 741c3161-d352-594a-89bd-8b486aa5c1c0

STIX ID: report--741c3161-d352-594a-89bd-8b486aa5c1c0

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: [email protected] (The Hacker News)

...
...

An attacker served tampered JavaScript from CDNs used by the WordPress plugins PushEngage, OptinMonster, and TrustPulse that, when loaded by a logged-in administrator, created an attacker-controlled admin account and installed a hidden plugin providing a web-shell backdoor; Sansec and PushEngage confirmed the campaign, provided IoCs and remediation steps (server-side scans, credential rotation), and noted the likely use of a compromised CDN key or other server breach as the entry vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.