Saturday, 1 November 2025
28.3 C
Singapore
24.5 C
Thailand
19.9 C
Indonesia
28.5 C
Philippines

Over a million WordPress sites attacked by a hacker in a month

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher.  The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over […]

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher. 

The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over 500,000 individual sites, according to Ram Gall from Wordfence.

Over the past month, Wordfence, a security vendor, detected attacks on over 900,000 sites from more than 24,000 IP addresses, all of which appear to be from the same malicious hacker. That is because the attacker is attempting to inject a similar JavaScript payload to insert a backdoor into a victim website and redirect visitors.

The attacks seek to exploit a few cross-site scripting vulnerabilities in the Newspaper theme, Easy2Map plug-in, and the Blog Designer plug-in. It also targeted the WP GDPR Compliance plug-in as well as the Total Donations plug-in.

Gall warned that the hacker behind all this might be able to pivot other vulnerabilities in the future.

The JavaScript used to attack the sites is designed to redirect users who are not logged-in to a malvertising URL. If the users are logged-in, the JavaScript tries to inject a malicious backdoor into a user’s current theme’s header file alongside another JavaScript, aiming to take control of the site. 

“The most important thing you can do in a situation like this is to keep your plug-ins up-to-date and to deactivate and delete any plug-ins that have been removed from the WordPress plug-in repository. The vast majority of these attacks are targeted at vulnerabilities that were patched months or years ago, and in plug-ins that don’t have a large number of users,” Gall advised.

“While we did not see any attacks that would be effective against the latest versions of any currently available plug-ins, running a web application firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” he added.

Hot this week

XDC Ventures acquires Contour Network and launches Stable-Coin Lab to reshape global trade finance

XDC Ventures acquires Contour Network and launches a Stable-Coin Lab to drive tokenised trade finance and faster cross-border settlements.

Clair Obscur fans speculate that the Expedition 33 update could introduce an evil Esquie boss fight

Fans speculate that Clair Obscur: Expedition 33's upcoming update may introduce a darker version of Esquie, following new artwork and social media hints.

Crunchyroll brings anime magic to AFA Singapore 2025 with immersive experiences and special guests

Crunchyroll returns to AFA Singapore 2025 with panels, screenings, and interactive anime experiences featuring Fire Force, Demon Slayer, and more.

Agnes AI surpasses 2 million users, showcasing Singapore’s growing AI innovation

Singapore-based Agnes AI surpasses 2 million users, advancing home-grown AI research and collaboration across Southeast Asia.

Neato cloud shutdown leaves robot vacuums limited to manual operation

Neato’s cloud services are shutting down, leaving its robot vacuums without app control and limited to manual operation.

Innovation drives legacy industries at TechInnovation 2025

Industry leaders at TechInnovation 2025 shared how innovation and collaboration are helping legacy businesses modernise for the future.

Informatica unveils Fall 2025 release to power the era of agentic AI

Informatica’s Fall 2025 release introduces new AI-driven data management tools to power agentic AI with trusted enterprise data.

Commvault launches Data Rooms to connect enterprise data with AI platforms securely

Commvault introduces Data Rooms, a secure platform enabling enterprises to safely activate and share backup data for AI use.

Most organisations struggle to keep pace with AI-powered ransomware, says CrowdStrike survey

CrowdStrike’s 2025 survey reveals 76% of organisations struggle to keep up with AI-powered ransomware attacks.

Related Articles

Popular Categories