HomeTechnologyBackdoors Found in Multiple WordPress Plugins, Impacting Thousands of Sites

Backdoors Found in Multiple WordPress Plugins, Impacting Thousands of Sites

Several WordPress plug-ins have been taken offline after a hidden backdoor was discovered, enabling attackers to inject malicious code into websites using them. The vulnerability surfaced following the acquisition of Essential Plugin by a new corporate owner, after which the backdoor was added to the plug-in’s source code. Anchor Hosting founder Austin Ginder revealed the issue in a blog post last week, describing it as a supply chain attack.

The backdoor remained inactive until earlier this month, when it began distributing malicious code to affected sites. Essential Plugin reports over 400,000 installations and 15,000 customers, while WordPress’ plug-in directory indicates more than 20,000 active installations of the compromised plug-ins.

Plug-ins allow owners of WordPress-based websites to extend the site’s functionality, but in doing so grant the plug-ins access to their installations, which can open these websites to malicious extensions and potential compromise. But Ginder warned that WordPress users are not notified of any plug-ins’ change in ownership, exposing users to potential takeover attacks by their new owners.

According to Ginder, this is the second hijack of a WordPress plug-in discovered in as many weeks. Security researchers have long warned of the risks of malicious actors buying software and changing its code in order to compromise a large number of computers around the world.

While the plug-ins have been removed from WordPress’ directory and now list their closure as “permanent,” Ginder warned that WordPress owners should check if they still have one of the malicious plug-ins installed and remove it. Ginder has a list of the affected plug-ins in the blog post. Representatives for Essential Plugin did not respond to a request for comment.

Source: Tech Crunch

Benjamin Mensah
Benjamin Mensahhttps://freshhope1.org
Benjamin Mensah [Freshhope] is a young man, very passionate about the youth of this Generation. Very friendly, reliable and very passionate about the things of God and all that I do. The mission is to inform, educate and entertain. Feel free to send your whatsapp messages to +233266550849 and call on +233242645676
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments

Janet Obenewaa on BEFORE AND AFTER “I DO”.
Nanayaw Frimpong on BEFORE AND AFTER “I DO”.
Nanayaw Frimpong on BEFORE AND AFTER “I DO”.
Abwaresen Joseph on DANGEROUS WOMEN TO STAY WITH
Asiedua Naomi on LOVE vs MONEY.
Ewuraa on LOVE vs MONEY.
Francis selorm Agbosu on Power of Anger
Ewuraa on Power of Anger
Ewuraba on THE POWER OF WORDS.