WordPress Plugin Backdoors Trigger Global Security Scare

Malicious code discovered in widely used plugins after a corporate acquisition raises fears of widespread website compromise across thousands of installations

1 min read
WordPress

Dozens of WordPress plugins have been taken offline after security researchers discovered hidden backdoors that were used to inject malicious code into websites relying on them, triggering a major supply chain security concern across the open-source ecosystem. The incident has raised alarms about how software ownership changes can introduce unseen risks into widely trusted digital tools.

    The issue came to light after Anchor Hosting founder Austin Ginder published a blog post warning of what he described as a supply chain attack targeting a WordPress plugin developer known as Essential Plugin. According to Ginder, the company was acquired last year by a new owner, after which a backdoor was allegedly introduced into the plugin’s source code. The malicious code reportedly remained inactive for months before being triggered earlier this month, at which point it began distributing harmful scripts to any website running the compromised plugins.

    Essential Plugin states that its software has been installed more than 400,000 times and is used by over 15,000 customers, while WordPress’ own plugin directory indicates that the affected tools were active on more than 20,000 websites. Because plugins integrate directly into website infrastructure and often operate with elevated permissions, they can serve as a powerful entry point for attackers once compromised.

    Security experts say the incident highlights a long-standing vulnerability in modern web development: the dependency on third-party plugins that can be altered after acquisition without clear notification to end users. Ginder warned that WordPress does not reliably inform users when a plugin changes ownership, leaving site operators unaware that tools they trust may have been modified in ways that expose them to attack.

    He also noted that this is the second reported case of plugin hijacking in just a few weeks, underscoring what researchers describe as a growing trend of software supply chain manipulation. Once attackers gain control of widely used codebases, they can potentially compromise thousands of websites simultaneously, making such incidents particularly damaging.

    In response, the affected plugins have been removed from the WordPress directory and marked as permanently closed. However, security warnings continue to circulate urging administrators to manually check their installations and remove any compromised plugins still present on their sites. As of now, Essential Plugin has not publicly responded to requests for comment regarding the allegations or the reported backdoor.

    Sri Lanka Guardian

    The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

    Leave a Reply

    Your email address will not be published.

    Latest from Blog