This Premium WordPress Plugin and Theme Has Been Compromised – Here’s How to Check Your Site Hasn’t Been Infected


  • Ongoing cyber attack compromises the BuddyBoss update system
  • Malicious updates steal admin credentials, Stripe keys and databases
  • Hundreds of websites are already affected; thousands more at risk, administrators urged to disable automatic updates and rotate credentials

A major cyber attack against websites running the BuddyBoss WordPress plugin is currently underway and users are being urged to secure their assets or risk complete compromise and site takeover.

BuddyBoss is a WordPress platform and theme that people can use to create online communities, membership sites, and e-learning platforms. It apparently has 50,000 customers, including 27,000 BuddyBoss Platform and BuddyBoss Theme package users.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top