WordPress Plugin Vulnerabilities

Various Plugins - Injected Backdoor

Description

Several plugins hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised their source code and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server.

Affects Plugins

Fixed in 2.5.4
No known fix
Fixed in 4.4.7.3
Fixed in 2.2.8
Fixed in 11.9.6
Fixed in 2.1.4
Fixed in 1.7.8

References

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2024-06-24 (about 1 year ago)
Added
2024-06-25 (about 1 year ago)
Last Updated
2024-07-05 (about 1 year ago)

Other