Thousands of WordPress websites hit by new malware attack, here’s what we know


  • Security researchers find more than 5,000 websites containing malicious code
  • The malware installs a plugin that steals login credentials and sensitive data.
  • The researchers recommended a series of mitigation measures.

Thousands of WordPress websites were observed running malware capable of creating a fraudulent administrator account and exfiltrating sensitive data through malicious plugins.

A new report from security researcher Himanshu Anand of c/side claims that at least 5,000 WordPress websites were found to be hosting a malicious script that creates an unauthorized administrator account with a username and password that can be found in the code.

Leave a Comment

Your email address will not be published. Required fields are marked *