news.mlab.sh
Back to the feed
supply-chain

OptinMonster WordPress plugin hacked in CDN supply-chain attack

High
Summary

A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN to inject malicious JavaScript code and create rogue administrator accounts, ultimately achieving full control of affected websites. The incident highlights the risks associated with CDN vulnerabilities and the importance of proactive security measures.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.