Tag: WordPress Sites

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
News

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

The hacking tools, activity logs, and target lists identifying over 1.4 million websites were all exposed when a cybercrime group left one of its own servers accessible on the internet for three weeks. The released files demonstrated to researchers how a mass site-hacking operation operates from the inside, even if many fewer were really compromised. The operation, which is now being monitored as WP-SHELLSTORM, is what SOCRadar refers to as a webshell access brokerage: a team that breaches websites on a large scale, installs a covert backdoor (a "webshell") on each, then bundles that access for sales. WordPress websites with outdated plugins had the most engagement. The Breeze caching plugin and Joomla's JCE editor were the two issues that mattered most whether you use WordPress ...
WP Maps Pro bug exploited to create admin accounts on WordPress sites
News

WP Maps Pro bug exploited to create admin accounts on WordPress sites

WordPress websites using a vulnerable version of the WP Maps Pro plugin—which permits the creation of rogue administrator accounts without authentication—are the target of hackers. The vulnerability affects WP Maps Pro versions 6.1.0 and earlier and is listed as CVE-2026-8732. It has a critical severity level. David Brown, a security researcher, found it and reported it. A premium WordPress plugin called WP Maps Pro is used to create interactive, editable maps and store locators. Several map suppliers, including OpenStreetMap and Google Maps, are supported. With over 15,800 sales on the Envato Market, the plugin is commonly utilized by companies, real estate websites, travel websites, directories, and organizations that require to display several locations on a map. A "tempora...
Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
News

Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites

Targeting both Windows and Apple macOS computers, a financially motivated threat actor with the codename UNC5142 has been seen abusing blockchain smart contracts to help spread information thieves like Atomic (AMOS), Lumma, Rhadamanthys (also known as RADTHIEF), and Vidar. In a research shared with The Hacker News, Google Threat Intelligence Group (GTIG) stated that UNC5142 is distinguished by its usage of hijacked WordPress websites and "EtherHiding," a technique that obscures dangerous code or data by storing it on a public blockchain, like the BNB Smart Chain. According to Google, as of June 2025, it has identified over 14,000 web pages with JavaScript injected that had behavior linked to a UNC5142, suggesting that it was indiscriminately targeting WordPress websites that were vu...
Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code Execution
News

Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code Execution

The WPML WordPress multilingual plugin contains a serious security vulnerability that, in some cases, might provide authorized users the ability to remotely execute arbitrary code. This issue affects all versions of the plugin prior to 4.6.13, which was released on August 20, 2024. It is tagged as CVE-2024-6386 (CVSS score: 9.9). The problem allows authorized attackers with Contributor-level access and above to execute code on the server since input validation and sanitization are absent. A well-liked plugin for creating multilingual WordPress websites is called WPML. More than a million installations are currently in use. The issue, according to security researcher stealthcopter, is with how the plugin handles shortcodes, which are used to add post content including audio rea...
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites
News

Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites

Threat actors are actively using a high-severity vulnerability in the WordPress plugin LiteSpeed Cache to create rogue administrator accounts on vulnerable websites. The information was obtained via WPScan, which reported that phony admin users with the identities wpsupp‑user and wp‑configuser had been created using the vulnerability (CVE-2023-40000, CVSS score: 8.3). Patchstack discovered CVE-2023-40000, a stored cross-site scripting (XSS) vulnerability that might allow an unauthorized user to escalate privileges through carefully constructed HTTP requests. Version 5.7.0.1 was released in October 2023, fixing the vulnerability. It's important to remember that the plugin was last updated read more Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites. ...
Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers
News

Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers

Researchers studying cybersecurity have uncovered a yet unreported malware that targets Android smartphones and evades detection by using hacked WordPress websites as relays for its real command-and-control (C2) servers. Code-named Wpeeper, the malware is an ELF binary that uses HTTPS to encrypt its C2 communications. According to experts from the QiAnXin XLab team, Wpeeper is a standard backdoor Trojan for Android systems that supports tasks including gathering sensitive device data, managing files and directories, uploading and downloading, and carrying out commands. The APK file serves as a covert backdoor delivery mechanism for the ELF code, which is embedded in a repackaged application that seems to be the UPtodown App Store app read more Android Malware Wpeeper Uses Comprom...
Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites
News

Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites

A serious security vulnerability in the WordPress plugin WP-Automatic is being actively targeted by threat actors, with the potential to enable site takeovers. The vulnerability, identified as CVE-2024-27956, has a CVSS score of 9.9 out of 10. It affects all plugin versions older than 3.9.2.0. According to a WPScan notice this week, this vulnerability, a SQL injection (SQLi) weakness, presents a serious risk because it allows attackers to create admin-level user accounts, upload malicious files, and potentially take complete control of compromised websites. The problem, according to the firm owned by Automattic, stems from the user authentication method of the plugin, which is easily gotten over to run arbitrary SQL queries against the database using specially constructed request...
Hackers deploy crypto drainers on thousands of WordPress sites
News

Hackers deploy crypto drainers on thousands of WordPress sites

Fake NFT and discount pop-ups are already appearing on around 2,000 compromised WordPress websites, tricking users into connecting their wallets to cryptocurrency drainers that automatically steal money. Last month, the website security company Sucuri revealed that hackers had gained access to almost 1,000 WordPress sites in order to spread cryptocurrency drainers through YouTube videos and malvertising. It is thought that when their initial campaign proved unsuccessful, the threat actors started using news scripts on the hacked websites to enable users' web browsers to be used as instruments for brute-forcing admin passwords on other websites. Approximately 1,700 brute-forcing websites were targeted in these attacks; well-known examples include the website of Ecuador's Associati...
Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
News

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

Over 39,000 WordPress websites have been infiltrated by a huge malware operation known as Sign1 in the last six months. Sign1 uses malicious JavaScript injections to divert users to scam websites. Sucuri reported last week that the most recent iteration of the malware is thought to have compromised at least 2,500 websites in the last two months alone. To give attackers the chance to upload their malicious code, the assaults involve inserting rogue JavaScript into genuine HTML widgets and plugins that permit the insertion of arbitrary JavaScript and other code. After being XOR-encoded, the JavaScript code is decoded and utilized to run a JavaScript file hosted on a remote server. This allows redirection to be made to a traffic distribution system (TDS) run by VexTrio, but only in ...