Thousands of WordPress websites hit in new malware attack, here’s what we know




  • Security researchers find more than 5,000 websites carrying a piece of malicious code
  • The malware installs a plugin that steals login credentials and sensitive data
  • The researchers recommended a number of mitigation measures

Thousands of WordPress websites were observed running malware able to create a rogue admin account and exfiltrated sensitive data through malicious plugins.

A new report from security researcher Himanshu Anand from c/side claims said at least 5,000 WordPress websites were found hosting a malicious script that creates an unauthorized admin account with a username and password that can be found in the code.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *