supply-chain
OptinMonster WordPress plugin hacked in CDN supply-chain attack
High
Summary
A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN to inject malicious JavaScript code and create rogue administrator accounts, ultimately achieving full control of affected websites. The incident highlights the risks associated with CDN vulnerabilities and the importance of proactive security measures.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data