DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

Quality: 8/10 Relevance: 9/10

Summary

A supply-chain attack compromised 30+ WordPress plugins from Essential Plugin, deploying a backdoor activated months after acquisition. The piece details the WPOS analytics backdoor, a C2 domain resolved via an Ethereum smart contract, WordPress.org's rapid plugin takedown, and the patching steps used to mitigate across a fleet, highlighting trust issues in plugin marketplaces and practical safeguards for small to mid-size sites.

🚀 Service construit par Johan Denoyer