Friday, 19 September 2025
28.2 C
Singapore
28.5 C
Thailand
19.7 C
Indonesia
28.5 C
Philippines

Over a million WordPress sites attacked by a hacker in a month

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher.  The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over […]

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher. 

The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over 500,000 individual sites, according to Ram Gall from Wordfence.

Over the past month, Wordfence, a security vendor, detected attacks on over 900,000 sites from more than 24,000 IP addresses, all of which appear to be from the same malicious hacker. That is because the attacker is attempting to inject a similar JavaScript payload to insert a backdoor into a victim website and redirect visitors.

The attacks seek to exploit a few cross-site scripting vulnerabilities in the Newspaper theme, Easy2Map plug-in, and the Blog Designer plug-in. It also targeted the WP GDPR Compliance plug-in as well as the Total Donations plug-in.

Gall warned that the hacker behind all this might be able to pivot other vulnerabilities in the future.

The JavaScript used to attack the sites is designed to redirect users who are not logged-in to a malvertising URL. If the users are logged-in, the JavaScript tries to inject a malicious backdoor into a user’s current theme’s header file alongside another JavaScript, aiming to take control of the site. 

“The most important thing you can do in a situation like this is to keep your plug-ins up-to-date and to deactivate and delete any plug-ins that have been removed from the WordPress plug-in repository. The vast majority of these attacks are targeted at vulnerabilities that were patched months or years ago, and in plug-ins that don’t have a large number of users,” Gall advised.

“While we did not see any attacks that would be effective against the latest versions of any currently available plug-ins, running a web application firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” he added.

Hot this week

Microsoft adds Steam and other store games to the Xbox PC app

Microsoft expands the Xbox PC app with Steam games, app integration, and cross-platform history sync for a unified gaming hub.

Proofpoint launches agentic AI solution for human communications intelligence

Proofpoint introduces its first agentic AI for Human Communications Intelligence, enabling real-time compliance and risk prevention.

Nothing to launch first AI-native devices next year

Nothing raises US$200m to develop AI-native devices and OS, with first products set to launch in 2026.

Singapore FinTech Festival marks 10th anniversary with focus on AI, tokenisation and quantum computing

Singapore FinTech Festival 2025 celebrates its 10th year with a focus on AI, tokenisation and quantum computing from 12 to 14 November.

Singapore ranks 5th in the 2025 Global Innovation Index

Singapore climbed to 5th in the 2025 Global Innovation Index, rising two spots in innovation outputs for its best ranking in over a decade.

Steam to end Windows 32-bit support in 2026

Steam will end support for 32-bit Windows on 1 January 2026, continuing only with 64-bit Windows 10 and 11.

Google to use hashes to remove non-consensual intimate imagery from search

Google partners with StopNCII to remove non-consensual intimate images from search using unique hashes.

You can turn off iOS 26 full-screen screenshot previews

Learn how to turn off iOS 26 full-screen screenshot previews while keeping editing tools accessible.

Anker recalls over 481,000 power banks after fire incidents

Anker recalls over 481,000 power banks after reports of fires, offering refunds and gift cards to affected consumers.

Related Articles

Popular Categories