Tag: WordPress websites

Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks
News

Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks

A weak version of the Post SMTP plugin is being used by over 200,000 WordPress websites, giving hackers access to the administrator account. With over 400,000 active installs, Post SMTP is a well-liked WordPress email delivery plugin. It is promoted as a more dependable and feature-rich alternative to the built-in "wp_mail()" function. A security researcher notified WordPress security company PatchStack about the vulnerability on May 23. The vulnerability was given a medium severity score of 8.8 and is currently known as CVE-2025-24000. Due to a malfunctioning access control mechanism in the plugin's REST API endpoints, which just checked if a user was logged in without determining their permission level, the security flaw impacts all Post SMTP versions up to 3.2.0. This impli...
Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers
News

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers

Researchers studying cybersecurity have revealed a new campaign that poses as a security plugin and targets WordPress websites. The plugin, called "WP-antymalwary-bot.php," has several functions to execute remote code, conceal itself from the admin dashboard, and preserve access. According to a research by Marco Wotschka of Wordfence, it also includes code that aids in the propagation of malware into other directories and inserts malicious JavaScript that serves advertisements, as well as pinging capability that can report back to a command-and-control (C&C) server. Since its initial discovery in late January 2025 during a site cleanup, numerous versions of the malware have been found in the wild. Several more names for the plugin read more about Fake Security Plugin on WordP...
Over 6000 WordPress hacked to install plugins pushing infostealers
News

Over 6000 WordPress hacked to install plugins pushing infostealers

Malicious plugins that propagate information-stealing malware by displaying phony software updates and errors are being installed on WordPress websites by hackers. Since compromised credentials are being used to infiltrate networks and steal data, information-stealing malware has become a global scourge for security defenders in recent years. Since 2023, a malicious campaign known as ClearFake has been used to spread information-stealing malware by displaying phony web browser update banners on hacked websites read more about Over 6000 WordPress hacked to install plugins pushing infostealers. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts
News

Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

A number of WordPress plugins have been compromised to introduce malicious code through backdoors, enabling the creation of rogue administrator accounts that may be used to carry out arbitrary tasks. As per the Wordfence security researcher Chloe Chamberland's report on Monday, the injected malware tries to create a new administrator user account and then transmits those information back to the attacker-controlled server. Furthermore, it seems that the threat actor also introduced malicious JavaScript into website footers, which spreads SEO spam across the page. The usernames of the admin accounts are "Options" and "PluginAuth," and the IP address 94.156.79[.]8 is where the account information was stolen read more about Multiple WordPress Plugins Compromised Hackers Create Rogue ...