Over 1 million WordPress sites at risk after hacked popular plugin – OptinMonster among those affected in CDN supply chain attack


  • Vulnerability in UpdraftPlus plugin on Awesome Motive’s marketing server enabled CDN compromise and malicious JavaScript injection
  • Malware targeting logged in WordPress admins, harvesting tokens and creating rogue accounts for full takeover
  • Site owners are encouraged to check for fake admin accounts (‘developer_api1’, ‘dev_xxxxxx’), hidden backdoor plugins and rotate credentials/security salts

More than a million WordPress websites were at risk of full website takeover after a vulnerability in a plugin enabled a large-scale supply chain attack. The attack was discovered over the weekend by e-commerce security outfit Sansec and later confirmed by the victim company.

According to the researchers, hackers found and exploited a vulnerability in the UpdraftPlus WordPress plugin running on a marketing server belonging to Awesome Motive, the company behind several popular WordPress products, including OptinMonster, TrustPulse and PushEngage.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top