news.mlab.sh
Back to the feed
malware

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

High
Image: The Hacker News
Summary

A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors that allowed them to gain administrative control of compromised sites. The attack leveraged a CDN and a compromised CDN API key, and while the initial entry point is disputed, the incident highlights the risks associated with vulnerable plugins and CDN configurations.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.