Friday, September 11, 2026

OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks

A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise.

The campaign also affects the TrustPulse and PushEngage plugins, both developed by Awesome Motive, significantly amplifying the attack surface across millions of WordPress deployments.

The attackers tampered with legitimate JavaScript files delivered via Awesome Motive’s CDN infrastructure, allowing malicious code to be silently injected into downstream websites without directly breaching individual servers.

This technique mirrors the 2024 Polyfill supply chain attack, where a single upstream compromise enabled mass exploitation at scale.

OptinMonster Plugin Vulnerability

The injected JavaScript payload is highly selective and designed to evade detection. It activates only when a logged-in WordPress administrator accesses the site, bypassing regular visitors and automated analysis environments such as headless browsers.

Once triggered, the malware performs environment checks, identifies WordPress paths, extracts REST and AJAX nonces, and creates unauthorized administrator accounts using multiple fallback mechanisms, including REST API endpoints and traditional admin workflows.

Notably, it plants a fixed administrator account (developer_api1) alongside randomized dev_xxxxxx accounts, ensuring persistence even if one vector fails.

Following account creation, the malware deploys a stealthy backdoor plugin that hides itself from both the WordPress dashboard and REST API endpoints.

This plugin enables full remote code execution via unauthenticated access, exposing endpoints that allow attackers to execute system commands and arbitrary PHP code, according to research published by the Sansec Forensics Team on June 13, 2026.

The payload also exfiltrates newly created credentials and site metadata using XOR encryption and base64 encoding, transmitting the data to a command-and-control (C2) infrastructure hosted at tidio.cc, a domain impersonating the legitimate tidio.com service.

Data exfiltration mechanisms include multiple fallback channels such as sendBeacon, fetch requests, XMLHttpRequest, and image beacons to ensure delivery reliability.

Security researchers confirmed active exploitation in the wild, with Patchstack reporting over 270 attempts to create rogue admin accounts across compromised sites within 48 hours.

The majority of these attempts leveraged the WordPress REST API, aligning with the malware’s execution logic. The attack infrastructure was operational before exploitation, with the malicious domain registered in April 2026 and linked to hosting provider Ultahost.

The infection window appears to have begun on June 12, 2026, with malicious scripts persisting on some CDN edges until June 14.

Awesome Motive has acknowledged the incident and attributed the breach to a compromised CDN API key obtained through exploitation of a vulnerability in the UpdraftPlus plugin on an internal system.

The company has since revoked compromised credentials, purged CDN caches, and migrated affected infrastructure. However, due to the nature of the attack, any site that loaded the malicious script while an administrator was logged in is considered compromised.

Security experts warn that remediation requires more than plugin updates. Affected site owners must audit administrator accounts, remove unauthorized users, and scan server-side files for hidden plugins, particularly those masquerading as legitimate utilities.

Full credential rotation and incident response procedures are strongly recommended, as attackers may already have achieved persistent access and code-execution capabilities.

Indicators of Compromise (IOCs)

CategoryIndicatorDetails
C2 Domaintidio.ccMalicious command-and-control domain
C2 IP84.201.6.54Hosted on Ultahost (AS214036)
C2 Endpointtidio.cc/cdn-cgi/pData exfiltration (OptinMonster/TrustPulse)
C2 Endpointtidio.cc/cdn-cgi/bData exfiltration fallback
C2 Endpointtidio.cc/cdn-cgi/lPayload generation
C2 Endpointtidio.cc/cdn-cgi/pe-pData exfiltration (PushEngage variant)
C2 Endpointtidio.cc/cdn-cgi/pe-bData exfiltration fallback
C2 Endpointtidio.cc/cdn-cgi/pe-lPayload generation
XOR KeyjX9kM2nP4qR6sT8vUsed for encoding stolen data
Backdoor MarkerWPM File Manager & ShellMalicious web shell interface
Rogue Admindeveloper_api1Fixed attacker-created admin account
Rogue Email[email protected]Linked to fixed admin account
Rogue Patterndev_xxxxxxRandomized admin usernames
Rogue Email Pattern[email protected]Randomized attacker emails
Malicious Plugincontent-delivery-helperDisguised plugin (v2.7.1)
Malicious Plugindatabase-optimizerDisguised plugin (v2.9.4)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News