Security Operations, Supply chain

WordPress plugins compromised after acquisition, leading to backdoor installation

Credit: Adobe Stock Images

As outlined in TechCrunch, dozens of WordPress plug-ins have been taken offline following the discovery of a malicious backdoor. This backdoor was intentionally inserted into the source code after a company acquired a suite of plug-ins, leading to the distribution of malicious code across numerous websites.

The attack vector was identified as a supply chain compromise affecting Essential Plugin, a provider with over 400,000 installs. Austin Ginder of Anchor Hosting reported that the new owner, who purchased Essential Plugin last year, embedded a backdoor into the plug-ins. This backdoor remained dormant until earlier this month, when it activated and began pushing malicious code to any site utilizing the affected plug-ins.

These plug-ins, which extend WordPress site functionality, were installed on over 20,000 active WordPress sites. The plug-ins have since been removed from the WordPress directory.

Source: TechCrunch

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds