Posts

Tag: Security Research

From a 7 KB file to a 13-year backdoor operation

Most plugin closures are uneventful. A developer stops responding, wp.org pulls the plugin, the listing goes dark, and that is the end of it.…

A Sold WordPress Plugin, a Hidden Update Channel, and 20,000 Backdoored Sites

I know you’ve heard this before however I’ve caught another plugin with a backdoor on wordpress.org. The plugin is Scroll To Top, slug scroll-top,…

WordPress Plugin Hijacked in 2020 Hid a Dormant Backdoor for Years

Twelve sites in our fleet were running a tampered version 5.2.3 of Quick Page/Post Redirect Plugin. The file hash did not match anything on…

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new…

How I Caught a WordPress Plugin Supply Chain Attack

A routine security alert led to uncovering a WordPress plugin supply chain attack. The Widget Logic plugin had changed hands, and the new owner…