Discussion

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Started by The Hacker News · 15 Jun 2026 14:22 · 23 Views · 0 Replies
Thread Starter #0
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it

Okumaya devam et...

You must be logged in to reply.

0 quotes selected