Skip to content

JOBUZO

  • News
  • Indonesia
  • Toggle search form
Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Posted on 14 April 2026 By jobuzo

Dozens of plug-ins for the widely used open source web blogging software WordPress are now offline after a backdoor was discovered in them, used to push malicious code to any website that relied on the plug-ins. The backdoor was discovered after a new corporate owner bought these plug-ins.

Anchor Hosting founder Austin Ginder sounded the alarm in a blog post last week describing a supply chain attack on a WordPress plug-in maker called Essential Plugin. Ginder said someone last year bought Essential Plugin and the backdoor was soon added to the plug-ins’ source code. The backdoor sat dormant until earlier this month when it activated and began distributing malicious code to any website with the plug-ins installed.

Essential Plugin says on its website that it has over 400,000 plug-in installs and more than 15,000 customers. WordPress’ plug-in install page says the affected plug-ins are in over 20,000 active WordPress installations.

Plug-ins allow owners of WordPress-based websites to extend the site’s functionality, but in doing so grant the plug-ins access to their installations, which can open these websites to malicious extensions and potential compromise. But Ginder warned that WordPress users are not notified of any plug-ins’ change in ownership, exposing users to potential takeover attacks by their new owners.

According to Ginder, this is the second hijack of a WordPress plug-in discovered in as many weeks. Security researchers have long warned of the risks of malicious actors buying software and changing its code in order to compromise a large number of computers around the world.

While the plug-ins have been removed from WordPress’ directory and now list their closure as “permanent,” Ginder warned that WordPress owners should check if they still have one of the malicious plug-ins installed and remove it. Ginder has a list of the affected plug-ins in the blog post.

News :<div>12 weeks' jail for school IT support technician who took upskirt videos of teachers</div>

Representatives for Essential Plugin did not respond to a request for comment.

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites


News

Post navigation

Previous Post: Why Sigenergy’s IPO ignited market frenzy with oversubscription of 1,000 times
Next Post: AI data center startup Fluidstack in talks for $1B round at $18B valuation months after hitting $7.5B, says report

Related Posts

Voice AI in India is hard. Wispr Flow is betting on it anyway. Voice AI in India is hard. Wispr Flow is betting on it anyway. News
WWE Saturday Night's Main Event: How to watch John Cena's final match for free WWE Saturday Night’s Main Event: How to watch John Cena’s final match for free News
Xi urges China, Tajikistan to promote cooperation in various fields Xi urges China, Tajikistan to promote cooperation in various fields News

Latest

  • Abreu has a two-run homer and 3 RBIs, Tolle pitches 6 scoreless innings and Red Sox beat Orioles 8-1
  • Someone Just Spotted the Samsung Galaxy Z Fold 8 Wide in Public
  • Chinese spies infiltrate LinkedIn with fake profiles and job offers, Five Eyes allies warn
  • Bluemercury’s Best Summer Perfumes Include Beachy Florals, Citrus Scents & More
  • Lovable signs multiyear deal with Google Cloud to up usage 5x, source says
  • Uber to put 500 data-collection vehicles on the road this year
  • Want to save the planet? Stop being so polite to AI chatbots
  • Chinese medical team donates supplies, offers free care to refugees in Zambia
  • Hezbollah: What to know about the Lebanese group at war with Israel
  • US Fed says Iran war driving ‘moderate-to-strong’ inflation

Copyright © 2025 JOBUZO. Disclaimers | Privacy Policies

Powered by PressBook Masonry Blogs