THIS WEEK: 3 WORDPRESS SUPPLY-CHAIN ATTACKS

 

🚨 Three Major WordPress Attacks Hit This Week — And These Aren't Ordinary Hacks




These are supply-chain attacks. Your website wasn't hacked directly. Instead, the companies behind the plugins you trust were compromised, and attackers used them as a gateway to infect WordPress sites.

Here's what happened:


⬛ ATTACK 01 — OptinMonster CDN


An UpdraftPlus vulnerability on an Awesome Motive marketing server allowed attackers to gain access and steal a CDN API key. They then injected malicious JavaScript into the CDN files of OptinMonster, TrustPulse, and PushEngage.

If your website loaded those files while you were logged in as an administrator, the malware could automatically create a hidden admin account and install a backdoor plugin—without any visible warning.More than 1.2 million websites were affected.


⬛ ATTACK 02 — ShapedPlugin Build Pipeline

Attackers breached ShapedPlugin's build pipeline, the system used to create and distribute plugin updates.They inserted a backdoor into the Pro plugin updates. If you installed the update through the normal WordPress update process, your site could become compromised.The free versions were not affected. Ironically, paying customers using the Pro versions became the primary targets.

CVE-2026-10735 | CVSS Score: 9.8


⬛ ATTACK 03 — Gravity SMTP API Leak


A vulnerable REST API endpoint lacked authentication, allowing anyone to retrieve approximately 365 KB of sensitive data, including email API keys, OAuth tokens, and email service credentials. Researchers observed more than 17 million exploitation attempts targeting this issue.

The Biggest Lesson

These three attacks used different entry points, but they all teach the same lesson:

Even if your WordPress core, themes, and plugins are fully updated, your website can still be compromised if a plugin vendor's CDN, build pipeline, or API infrastructure is breached. Trusting a plugin isn't just about its code—it's about trusting the vendor's entire security ecosystem. Stay informed. Verify your plugins. Monitor your websites. Security doesn't end with clicking "Update." If you need help checking whether your website is affected, feel free to send me a message.


#WordPressSecurity #WordPress #CyberSecurity #SupplyChainAttack #WebsiteSecurity #InfoSec #GetShielded


GetShielded


Comments

Popular posts from this blog

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Is Your Hosting Really Protecting You?