malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors that allowed them to gain administrative control of compromised sites. The attack leveraged a CDN and… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor