WordPress key feature has been diverted to display a malicious code, spam images


  • Sucuri researchers have found malware hiding in the Mu-Plugins repertoire
  • Malware has redirected visitors, served spam and could even drop malware
  • The sites have been compromised via vulnerable plugins, bad administrative passwords and more

A special repertoire in WordPress is abused to host a malicious code, said the researchers, warning that the code allows threats to remain persistent on vulnerable websites, while executing arbitrary code, redirecting people to malicious websites and by displaying spam and unwanted advertisements.

SUCURI researchers have discovered that threat actors hid the malicious code in “mu-plagins” (abbreviation of plugins for essential use), a repertoire that stores plugins that are automatically activated and cannot be deactivated via the administration panel.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top