Back to News
technology

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Zack Whittaker
Loading...
3 min read
0 likes
⚡ Quantum Brief
A supply chain attack compromised dozens of WordPress plugins after a corporate acquisition introduced hidden backdoors, affecting over 20,000 active websites. The malware remained dormant until April 2026 before activating. Essential Plugin, with 400,000+ installs, was sold to an unnamed buyer who embedded malicious code into its products. Security researcher Austin Ginder exposed the breach, warning of silent ownership changes leaving users vulnerable. The backdoor enabled remote code execution, allowing attackers to inject malware into websites using the infected plugins. WordPress removed the plugins permanently but urged administrators to verify and delete them manually. This marks the second WordPress plugin hijacking in weeks, highlighting risks of malicious acquisitions in open-source ecosystems. Experts warn such attacks exploit trust in legacy software with broad reach. WordPress’s lack of ownership-change notifications exacerbates risks, as users remain unaware of potential compromises. Ginder’s blog post lists affected plugins, but Essential Plugin has not publicly commented.
AI Audio Summary
0:00 / 0:00
Click to play
f2806353-1eff-4aa8-92d0-13b73f21518c.jpeg
Quantum News · Media Library

The first StrictlyVC of 2026 hits San Francisco. Tickets are going fast. Register now.Save up to $680 on your Disrupt 2026 pass. Ends 11:59 p.m. PT tonight. REGISTER NOW. Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us Dozens of plug-ins for the widely used open source web blogging software WordPress are now offline after a backdoor was discovered in them, used to push malicious code to any website that relied on the plug-ins. The backdoor was discovered after a new corporate owner bought these plug-ins.Anchor Hosting founder Austin Ginder sounded the alarm in a blog post last week describing a supply chain attack on a WordPress plug-in maker called Essential Plugin. Ginder said someone last year bought Essential Plugin and the backdoor was soon added to the plug-ins’ source code. The backdoor sat dormant until earlier this month when it activated and began distributing malicious code to any website with the plug-ins installed.Essential Plugin says on its website that it has over 400,000 plug-in installs and more than 15,000 customers. WordPress’ plug-in install page says the affected plug-ins are in over 20,000 active WordPress installations.Plug-ins allow owners of WordPress-based websites to extend the site’s functionality, but in doing so grant the plug-ins access to their installations, which can open these websites to malicious extensions and potential compromise. But Ginder warned that WordPress users are not notified of any plug-ins’ change in ownership, exposing users to potential takeover attacks by their new owners.According to Ginder, this is the second hijack of a WordPress plug-in discovered in as many weeks. Security researchers have long warned of the risks of malicious actors buying software and changing its code in order to compromise a large number of computers around the world.While the plug-ins have been removed from WordPress’ directory and now list their closure as “permanent,” Ginder warned that WordPress owners should check if they still have one of the malicious plug-ins installed and remove it. Ginder has a list of the affected plug-ins in the blog post.Representatives for Essential Plugin did not respond to a request for comment.Topics Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com. StrictlyVC kicks off the year in SF. Get in the room for unfiltered fireside chats with industry leaders, insider VC insights, and high-value connections that actually move the needle. Tickets are limited. An Amazon warehouse worker died on the job at Oregon facility Stanford report highlights growing disconnect between AI insiders and everyone else Sam Altman responds to ‘incendiary’ New Yorker article after attack on his home France to ditch Windows for Linux to reduce reliance on US tech YouTube Premium and YouTube Music are getting more expensive This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a ‘fighter jet for orbit.’ Developer of VeraCrypt encryption software says Windows users may face boot-up issues after Microsoft locked his account © 2026 TechCrunch Media LLC.

Read Original

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.