Several WordPress.org Plugins <= Various Versions - Injected Backdoor
criticalSeveral plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...
- CVSS:
- 10
- Affected:
- 2.2.5 – 2.5.2
- Fixed in:
- 2.5.4
- Disclosed:
- Jun 24, 2024