Trusted WordPress update backdoors at least 1,500 customer sites

Trusted WordPress update backdoors at least 1,500 customer sites. A trusted update channel delivered malicious code to at least one thousand five hundred WordPress sites.

Daily Cyber News: Trusted WordPress update backdoors at least 1,500 customer sites

A trusted update channel delivered malicious code to at least one thousand five hundred WordPress sites. An attacker compromised the Admin Menu Editor Pro maintainer’s website and inserted a web shell and hidden user account into versions 2.35 and 2.36. The developer estimated that at least 230 customers installed the first malicious update, often across multiple sites, and warned that the total number could be higher.

Key context: Sites that installed the poisoned versions may remain accessible to the attacker even after the plugin itself is removed.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, Trusted WordPress, Trusted, WordPress, backdoors, least, customer, sites.

Trusted WordPress update backdoors at least 1,500 customer sites
Broadcast by