Peter Makohon’s Post

View profile for Peter Makohon, graphic

Global Head of Cyber Threat Management at AIG

WordPress Security Alert: Backdoor Discovered in Popular Plugins A serious security issue has been uncovered affecting multiple WordPress plugins with over 35,000 combined installations. Security experts at Wordfence have identified a supply chain attack compromising five plugins from the official WordPress.org repository[1]. The affected plugins include: - Social Warfare (30,000+ active installations) - Blaze Widget - Wrapper Link Element - Contact Form 7 Multi-Step Addon - Simply Show Hooks The malicious code injected into these plugins allowed attackers to create unauthorized administrator accounts and inject SEO spam across compromised websites. The initial compromise is believed to have occurred on June 21, 2024, with ongoing updates by the attackers[1]. Wordfence's Threat Intelligence team detected the issue on June 24, 2024, after the WordPress.org Plugin Review team reported the compromise of the Social Warfare plugin. Versions 4.4.6.4 to 4.4.7.1 of Social Warfare were found to be creating users with administrative privileges[1]. In response, the compromised plugins have been delisted from the WordPress.org repository. The Plugin Review Team has released a clean updated version (4.4.7.3) of Social Warfare, and website administrators are strongly advised to update immediately[1]. If you're using any of the affected plugins, take immediate action: 1. Initiate incident response mode 2. Review administrative accounts for unauthorized access 3. Conduct thorough malware scans 4. Update to patched versions or remove the plugins entirely. Sources [1] Backdoor found in WordPress plugins with 35,000+ installations https://lnkd.in/gXg5Fqxc [2] Backdoor Found in WordPress Plugin With More Than 200,000 ... https://lnkd.in/g84FnECX [3] Backdoor found in WordPress plugins with 35000 installations https://lnkd.in/gsYk5vSU [4] Hacker News - All | Search powered by Algolia https://lnkd.in/gK8C8v93 [5] Alex Ivanovs (@stackdiary) / X https://lnkd.in/gsPqpz3x

Blog Tool, Publishing Platform, and CMS - WordPress.org

Blog Tool, Publishing Platform, and CMS - WordPress.org

wordpress.org

To view or add a comment, sign in

Explore topics