#Plugin Security

Every story tagged Plugin Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

1 story · open in the command center

  • Security & PrivacyHacker News3m

    Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them

    A threat actor purchased a portfolio of 30+ WordPress plugins for six figures on Flippa, planted sophisticated backdoors that remained dormant for 8 months, then weaponized them to inject SEO spam using blockchain-based command-and-control infrastructure that resists traditional takedowns. This supply chain attack demonstrates that legitimate software acquisitions are being exploited as attack vectors, with malicious code surviving even official remediation efforts (WordPress.org's forced update removed the phone-home mechanism but left injected malware in wp-config.php intact). IT organizations face significant risk from third-party plugins and extensions, as trusted software can be compromised through ownership transfers that bypass traditional security vetting processes.

Browse all tags