Ongoing Attack Campaign Exploits Various WordPress Plugins: Researchers

Date:

Share post:

Security researchers found that cybercriminals are using WordPress plugins for an ongoing attack campaign targeting numerous WordPress sites. The researchers are from the security firm WordFence. The attackers are exploiting vulnerabilities in the WordPress plugins to divert traffic from the victim’s site to malicious websites.

“Over the past few weeks, our Threat Intelligence team has been tracking an active attack campaign targeting a selection of new and old WordPress plugin vulnerabilities. These attacks seek to maliciously redirect traffic from victims’ sites to several potentially harmful locations. Each of the vulnerabilities targeted by this campaign has been public for some time, and users are protected either by individual firewall rules or generic protections built into the plugin,” the researchers said in an official statement.

According to the researchers, the flaws in the WordPress plugins allow an attacker to get Admin access by modifying WordPress options and also enables the attacker to inject malicious 301 redirects on the targeted website.

Researchers said that various other WordPress plugins are under exploitation in the ongoing campaign including, Yellow Pencil Visual Theme Customizer, Blog Designer, Woocommerce User Email Verification, Coming Soon, and Maintenance Mode.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...