Monday, April 28, 2025
Homecyber securityHackers Exploit Multiple WordPress Plugins to Hack Websites & Create Rogue Admin...

Hackers Exploit Multiple WordPress Plugins to Hack Websites & Create Rogue Admin Accounts

Published on

SIEM as a Service

Follow Us on Google News

Wordfence Threat Intelligence team identified a significant security breach involving multiple WordPress plugins.

 The initial discovery was made when the team found that the Social Warfare plugin had been injected with malicious code on June 22nd, 2024.

This discovery was based on a forum post by the WordPress.org Plugin Review team.

- Advertisement - Google News

Upon further investigation, Wordfence identified four additional plugins that were similarly compromised.

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

The affected plugins include:

  • Social Warfare (versions 4.4.6.4 – 4.4.7.1)
  • Blaze Widget (versions 2.2.5 – 2.5.2)
  • Wrapper Link Element (versions 1.0.2 – 1.0.3)
  • Contact Form 7 Multi-Step Addon (versions 1.0.4 – 1.0.5)
  • Simply Show Hooks (version 1.2.1)

Immediate Actions and Recommendations

Wordfence has contacted the WordPress plugins team to alert them about the compromised plugins.

Although there has been no official response, the affected plugins have been delisted.

Users are advised to update the patched versions where available or remove the plugins entirely if no patch exists.

The injected malware attempts to create a new administrative user account and sends the details to an attacker-controlled server.

Additionally, malicious JavaScript is injected into the website’s footer, adding SEO spam.

The malware is not heavily obfuscated, making it easy to follow and remove.

Indicators of Compromise and Next Steps

The Wordfence team is conducting a deeper analysis and developing malware signatures to detect these compromised plugins.

The Wordfence Vulnerability Scanner will notify users running the affected versions.

Immediate steps include checking for unauthorized administrative accounts and running a complete malware scan using the Wordfence plugin or CLI.

Indicators of Compromise:

  • Server IP Address: 94.156.79.8
  • Generated Admin Usernames: Options, PluginAuth

If you have any of these plugins installed, consider your site compromised and take immediate action.

For detailed guidance on cleaning your WordPress site, visit the Wordfence website or sign up for their incident response services.

Stay vigilant and ensure your WordPress installations are secure to prevent further exploitation.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...