Thousands of WordPress Websites Hit by New Malware Attack, Here’s What We Know


  • Security researchers discover more than 5,000 websites containing malicious code
  • Malware installs plugin that steals login credentials and sensitive data
  • Researchers recommended a number of mitigation measures

Thousands of WordPress websites have been observed running malware capable of creating a malicious administrator account and exfiltrating sensitive data via malicious plugins.

A new report from security researcher Himanshu Anand of c/side claims that at least 5,000 WordPress websites host a malicious script that creates an unauthorized administrator account with a username and password that can be found in the code.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top