logo

Balada Injector Infects Over 7,100 WordPress Sites Using Plugin Vulnerability

ID: 9c68c02a-f7b2-51b9-9515-e3da916fba1f

STIX ID: report--9c68c02a-f7b2-51b9-9515-e3da916fba1f

Feed Name: The Hacker News

Threat Score
76/100

Date Published: 2024-01-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Thousands of WordPress sites have been compromised by the Balada Injector campaign exploiting a high-severity Popup Builder flaw (CVE-2023-6000, CVSS 8.8) to inject JavaScript hosted on specialcraftbox.com, install backdoor plugins (e.g., wp-felody.php, sasas), create rogue administrators, and redirect visitors to scam pages; Sucuri observed over 7,100 sites affected in the latest wave and the operation has reportedly been active since 2017 with wide impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.