Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN…
- Vulnerability in UpdraftPlus plugin on Awesome Motive’s marketing server enabled CDN compromise and malicious JavaScript injection
- Malware targeted logged‑in WordPress admins, harvesting tokens and creating rogue accounts for full takeover
- Site owners urged to check for fake admin accounts (‘developer_api1’, ‘dev_xxxxxx’), hidden backdoor plugins, and rotate credentials/security salts
More than a million WordPress websites were at risk of full website takeover, after a vulnerability in a plugin enabled a large-scale supply-chain attack. The attack was spotted over the weekend by the ecommerce security outfit Sansec, and later confirmed by the victim company.
According to the researchers, hackers found and exploited a vulnerability in the UpdraftPlus WordPress plugin running on a marketing server belonging to Awesome Motive, the company behind multiple popular WordPress products including OptinMonster, TrustPulse, and PushEngage.
Even though the vulnerable server was not part of the production environment, it stored credentials for the company’s content delivery network (CDN),...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE