
A significant security breach has been uncovered in numerous plugins for the highly utilized open-source blogging platform, WordPress. These plugins have been taken offline following the discovery of a backdoor that allowed the injection of malicious code into websites using them. The alarming revelation came to light after a new corporate owner acquired the plugin developer, Essential Plugin. Austin Ginder, the founder of Anchor Hosting, raised the alarm in a recent blog post, detailing a supply chain attack that compromised the integrity of the plugins. Ginder explained that after the acquisition last year, the backdoor was inserted into the source code of these plugins. Initially dormant, the backdoor activated earlier this month, resulting in the distribution of harmful code to any website utilizing the compromised plugins. Essential Plugin itself claims to have over 400,000 installations and serves more than 15,000 customers. The WordPress plugin directory indicates that the affected plugins are present in over 20,000 active installations. Plugins are designed to enhance the functionality of WordPress sites, but they also grant access to their installations, potentially exposing websites to malicious interference. Ginder cautioned that users are often unaware of changes in plugin ownership, which can leave them vulnerable to takeover attempts by new owners. This incident marks the second reported hijacking of a WordPress plugin within just two weeks, highlighting ongoing concerns from security experts regarding the risks associated with malicious actors acquiring software and altering its code. While the compromised plugins have been permanently removed from the WordPress directory, Ginder urged WordPress site owners to verify whether they still have any of these malicious plugins installed and to remove them immediately. A list of the affected plugins is available in Ginder's blog post. Attempts to reach representatives from Essential Plugin for a statement have gone unanswered.
The recent unveiling of Kimi, an AI model from the Chinese company Moonshot AI, has sparked renewed discussions about Am...
TechCrunch | Jul 26, 2026, 20:05
This past week has been challenging for the stock market, driven by several significant forces that have created turbule...
CNBC | Jul 25, 2026, 20:05
In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...
TechCrunch | Jul 25, 2026, 21:00
In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...
Business Insider | Jul 25, 2026, 20:30Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...
TechCrunch | Jul 25, 2026, 19:50