Thousands of WordPress Sites Hit in New Malware Attack, Here’s What We Know


  • Security researchers find more than 5,000 websites with a piece of malicious code
  • The malware installs a plugin that steals login credentials and sensitive data
  • The researchers recommended a number of mitigation measures

Thousands of WordPress sites were observed running malware that could create a rogue administrator account and exfiltrate sensitive data through malicious plugins.

A new report by security researcher Himanshu Anand of c/side claims that at least 5,000 WordPress sites were found hosting a malicious script that creates an unauthorized administrator account with a username and password that can be found in the code.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top