
Discover how a backdoor in popular WordPress plugins threatens thousands of sites. Learn about the vulnerability and its activation in this article.
Overview of the Backdoor Incident
Dozens of popular WordPress plugins are now offline after a backdoor was discovered, allowing malicious code distribution to websites that rely on them. This incident highlights significant security vulnerabilities within software supply chains.
Discovery and Context
The discovery of this vulnerability came through a blog post by Austin Ginder, founder of Anchor Hosting, who first raised the alarm last week. Ginder detailed how a new corporate owner had purchased Essential Plugin, which has over 400,000 plugin installs and more than 15,000 customers. The backdoor was added to the plug-ins' source code shortly after the acquisition.
Activation and Impact
Earlier this month, the dormant backdoor activated, distributing malicious code through these plugins. With approximately 20,000 active WordPress installations currently using the affected plug-ins, the potential for widespread compromise is considerable. Ginder emphasized that users are not notified of any changes in ownership, thereby exposing them to takeover risks by new owners.
Broader Implications
This incident underscores the ongoing threat from malicious actors who buy and alter software code to gain access to vast networks of computers worldwide. While Essential Plugin has since removed its plugins from the WordPress directory, Ginder advised users to check for any remaining malicious plugins and remove them immediately.
Industry Response and Expert Opinions
Ginder warned that this is the second such incident discovered in just two weeks, indicating a growing trend. Security researchers have long cautioned about supply chain attacks, but such incidents remain challenging to detect and mitigate due to the lack of notification mechanisms for plugin ownership changes.
Source: Read Original Article
Post a Comment