Blog/Cybersecurity/Article
Cybersecurity

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

The Hacker News 10h ago Jun 15, 2026 1 min read

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the …

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
This is a summary curated by STELNEX. Read the complete article at The Hacker News.
Read full article →
SHARE