Home About Services Projects Blog Contact Policy
Security Alert

Over 30 WordPress Plugins
Compromised via Backdoor

EA

Author

Eslam Abdullah

Date

Reading Time

5 Min Read

WordPress plugin backdoor supply-chain attack 2026

In a shocking development for the WordPress ecosystem, security researchers have uncovered a massive supply chain attack targeting over 30 popular plugins. The attack, which came to light in late April 2026, involves the injection of malicious backdoors that allow unauthorized access to the underlying server.

How the Attack Happened

The attacker utilized a "supply chain" method, where they systematically acquired established plugins from their original developers. Once control was handed over, malicious code was added to the next scheduled update. Because these plugins already had thousands of active installations, the malicious code spread rapidly through the automated update system.

"This is one of the most sophisticated supply chain attacks we've seen in the WordPress space in years. The patience required to acquire 30 different assets speaks to a high level of organization," says Eslam Abdullah.

Technical Details

The backdoor is typically hidden within obfuscated JavaScript files or disguised as innocuous utility functions. Once active, it establishes a WebSocket connection to a Command & Control (C2) server, allowing the attacker to execute arbitrary PHP code, dump databases, or even use the server as a proxy for further attacks.

  • Acquisition of 32 different plugin assets over 6 months.
  • Injection of highly obfuscated eval() calls.
  • Potential impact on over 500,000 websites globally.

What You Should Do

If you are using any third-party plugins, it is recommended to perform a thorough audit of your site. Check for unauthorized administrative users, monitor for unusual outgoing traffic, and ensure you have a "Clean" backup from before April 15th.