"Several Plugins Compromised in WordPress Supply Chain Attack"
"Several Plugins Compromised in WordPress Supply Chain Attack"
According to security researchers at Defiant, malicious code injected over the past week in five WordPress plugins creates a new administrative account. The code was discovered on Monday after the researchers learned that a threat actor had taken over the Social Warfare plugin and added the malicious code in recent versions. The researchers noted that starting June 22, several versions of the plugin were released with the injected code inside.