Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites.

When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

An American Mosaic (interactive map of ancestry census data)

An American Mosaic (interactive map of ancestry census data) Source: Hacker News

So Reddit has decided that plain HTML is unsafe

So Reddit has decided that plain HTML is unsafe Source: Hacker News

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its