Multiple reports say attackers compromise widely used WordPress marketing and engagement plugins by tampering with trusted JavaScript files. The outlets describe affected products including PushEngage, OptinMonster, and TrustPulse (with OptinMonster and related plugins also referenced as being used on large numbers of sites). According to the reports, the malicious code is designed to run when a site administrator is logged in and loads the affected file, rather than triggering for ordinary visitors. In those conditions, the injected script creates an administrator account under the attacker’s control and installs a hidden plugin that provides a persistent backdoor. The Hacker News describes the backdoor as opening a route for further access, enabled by the newly created administrative user and the concealed plugin. Infosecurity Magazine adds an estimate that the tampering has impacted roughly 1.2 million WordPress sites. The reports collectively indicate the activity relies on compromising or altering plugin-supplied scripts rather than exploiting a WordPress core vulnerability, and it targets ongoing use by administrators to gain elevated access and persistence.
Hijacked WordPress Plugin Scripts Used to Install Backdoors on Popular Sites
Multiple reports say attackers compromise widely used WordPress marketing and engagement plugins by tampering with trusted JavaScript files. The outlets describe affected products including PushEngage...
- Attackers tamper with JavaScript files used by WordPress sites running plugins including PushEngage, OptinMonster, and TrustPulse.
- The injected code runs when a logged-in administrator loads the affected file, not when ordinary visitors visit.
- The code creates an administrator account controlled by the attacker.
- A hidden plugin is installed to maintain persistence and enable a backdoor.
- Infosecurity Magazine reports an estimated impact of about 1.2 million WordPress sites.
Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites
2 months agoAn attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
2 months ago
NYT Connections Sports Edition: outlets publish hints and answers for multiple dates
Multiple outlets—including Mashable, CNET, and The Athletic—publish daily coverage for the New York Times word game Conn...
Georgia Grey scores to put Titans ahead against Canberra
Georgia Grey scores for the Titans, putting them in front against Canberra. The match report describes Grey splitting Ca...
Bunker overturns decision to award Raiders try, stunning players
Canberra’s Elise Simpson is awarded a try after a Bunker review, leaving players including Paul Gallen and Ruan Sims stu...