WordPress plugin attacks create hidden administrator access
Daily Cyber News: WordPress plugin attacks create hidden administrator access
Attackers are exploiting flaws in two WordPress plugins to install backdoors and create hidden administrator access. Ninja Forms is installed on more than five hundred thousand sites, while WPC Product Bundles for WooCommerce is active on more than thirty thousand. The attack plants malicious JavaScript in a form submission or order.
Key context: That cleanup warning matters because compromised sites can retain hidden accounts and secret login routes even after the visible malicious plugin is deleted.
Additional detail: The larger lesson is that prevention and incident cleanup are separate jobs.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, WordPress, plugin, attacks, create, hidden, administrator, access.