WordPress sites under attack – expert report says dozens of plugins hijacked to target thousands of sites


  • Malicious actor purchased 31 WordPress plugins from Essential Plugin
  • Updates injected backdoors, provides full site access
  • Spam campaigns hidden from owners, C2 solved via Ethereum smart contract

A hacker bought more than 30 legitimate WordPress plugins and abused their good reputation to infect tens of thousands of websites with backdoors.

Austin Ginder, founder of Anchor Hosting, reported how a client recently alerted him to a known plugin suddenly allowing unauthorized third-party access. The investigation led him to a somewhat worrying discovery: a company that developed 31 WordPress plugins, both free and premium versions, was sold in early 2025 to a person who calls himself “Kris”.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top