WordPress Plugin Vulnerabilities
Various Plugins - Injected Backdoor
Description
Several plugins hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised their source code and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server.
Affects Plugins
References
CVE
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2024-06-24 (about 1 year ago)
Added
2024-06-25 (about 1 year ago)
Last Updated
2024-07-05 (about 1 year ago)