Over 30 WordPress Plugins
Compromised via Backdoor
Author
Eslam Abdullah
Date
Reading Time
5 Min Read
In a shocking development for the WordPress ecosystem, security researchers have uncovered a massive supply chain attack targeting over 30 popular plugins. The attack, which came to light in late April 2026, involves the injection of malicious backdoors that allow unauthorized access to the underlying server.
How the Attack Happened
The attacker utilized a "supply chain" method, where they systematically acquired established plugins from their original developers. Once control was handed over, malicious code was added to the next scheduled update. Because these plugins already had thousands of active installations, the malicious code spread rapidly through the automated update system.
Technical Details
The backdoor is typically hidden within obfuscated JavaScript files or disguised as innocuous utility functions. Once active, it establishes a WebSocket connection to a Command & Control (C2) server, allowing the attacker to execute arbitrary PHP code, dump databases, or even use the server as a proxy for further attacks.
- Acquisition of 32 different plugin assets over 6 months.
- Injection of highly obfuscated eval() calls.
- Potential impact on over 500,000 websites globally.
What You Should Do
If you are using any third-party plugins, it is recommended to perform a thorough audit of your site. Check for unauthorized administrative users, monitor for unusual outgoing traffic, and ensure you have a "Clean" backup from before April 15th.