WordPress Websites Under Attack: Expert Report Says Dozens of Plugins Hijacked to Target Thousands of Sites



  • A malicious actor purchased 31 WordPress plugins from Essential Plugin
  • Updates injected backdoors, granting full access to the site
  • Spam campaigns hidden from owners, C2 solved by Ethereum smart contract

A hacker purchased more than 30 legitimate WordPress plugins and abused their good reputation to infect tens of thousands of websites with backdoors.

Austin Ginder, founder of Anchor Hosting, reported how a customer recently alerted him to a known plugin that was suddenly allowing access by unauthorized third parties. The investigation led him to a somewhat disturbing discovery: a company that developed 31 WordPress plugins, both free and premium versions, was sold in early 2025 to a person who called himself “Kris.”



Leave a Comment

Your email address will not be published. Required fields are marked *