Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites.

When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: Voice driven murder mystery, Interview AI suspects with your voice

Show HN: Voice driven murder mystery, Interview AI suspects with your voice Source: Hacker News

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1

Why current LLM costs are not sustainable

Why current LLM costs are not sustainable Source: Hacker News