Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Posted on April 14, 2026April 14, 2026 By safdargal12 No Comments on Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites
Blog


Dozens of plug-ins for the widely used open source web blogging software WordPress are now offline after a backdoor was discovered in them, used to push malicious code to any website that relied on the plug-ins. The backdoor was discovered after a new corporate owner bought these plug-ins.

Anchor Hosting founder Austin Ginder sounded the alarm in a blog post last week describing a supply chain attack on a WordPress plug-in maker called Essential Plugin. Ginder said someone last year bought Essential Plugin and the backdoor was soon added to the plug-ins’ source code. The backdoor sat dormant until earlier this month when it activated and began distributing malicious code to any website with the plug-ins installed.

Essential Plugin says on its website that it has over 400,000 plug-in installs and more than 15,000 customers. WordPress’ plug-in install page says the affected plug-ins are in over 20,000 active WordPress installations.

Plug-ins allow owners of WordPress-based websites to extend the site’s functionality, but in doing so grant the plug-ins access to their installations, which can open these websites to malicious extensions and potential compromise. But Ginder warned that WordPress users are not notified of any plug-ins’ change in ownership, exposing users to potential takeover attacks by their new owners.

According to Ginder, this is the second hijack of a WordPress plug-in discovered in as many weeks. Security researchers have long warned of the risks of malicious actors buying software and changing its code in order to compromise a large number of computers around the world.

While the plug-ins have been removed from WordPress’ directory and now list their closure as “permanent,” Ginder warned that WordPress owners should check if they still have one of the malicious plug-ins installed and remove it. Ginder has a list of the affected plug-ins in the blog post.

Representatives for Essential Plugin did not respond to a request for comment.



Source link

Post Views: 21

Post navigation

❮ Previous Post: Google’s Windows app is now available everywhere
Next Post: Physicists think they’ve resolved the proton size puzzle ❯

You may also like

Apple TV MDM enrollment: A complete guide for IT teams
Blog
Apple TV MDM enrollment: A complete guide for IT teams
May 7, 2026
It’s time for Samsung’s S Pen to evolve or die
Blog
It’s time for Samsung’s S Pen to evolve or die
May 30, 2026
Android 16 Bug Allows Apps to Ignore VPNs and Leak IP Addresses
Blog
Android 16 Bug Allows Apps to Ignore VPNs and Leak IP Addresses
May 15, 2026
Apple’s camera-equipped AirPods take a big step toward launch
Blog
Apple’s camera-equipped AirPods take a big step toward launch
May 7, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Persona 6 exists, and that’s all we know
  • an electronic calculator from 1948
  • WWDC 2026 Live: Apple’s New Siri, iOS 27, Tim Cook and More
  • Here's how you can get $150 off the Galaxy S26 Ultra from Samsung.com
  • AT&T, Verizon, and T-Mobile all sold your location data and the Supreme Court just ruled

Recent Comments

  1. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown