Infosecurity-Magazine Supply Chain Attack Compromises Popular WordPress Plugins Affecting 1.2 Million Sites
Article Content
- •Malicious JavaScript was served to over 1.2 million sites via Awesome Motive's CDN.
- •The attack exploited a vulnerability in the UpdraftPlus plugin to gain access to CDN credentials.
- •Affected sites should be treated as compromised if an admin was logged in during the attack window.
A supply chain attack has compromised the OptinMonster, TrustPulse, and PushEngage WordPress plugins, impacting over 1.2 million sites. Attackers exploited a known vulnerability in the UpdraftPlus plugin to gain access to Awesome Motive's CDN, allowing them to serve malicious JavaScript directly to customer sites. The malware activates when a logged-in administrator visits an infected site, creating a rogue admin account and installing a hidden backdoor plugin. This backdoor can execute arbitrary PHP code and communicate with a lookalike domain of Tidio. The attack was discovered by Sansec and occurred on June 12, 2026. Awesome Motive has since remediated the issue and rotated all credentials, but affected site owners are advised to treat their sites as compromised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Content Delivery Helper and Awesome Motive in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…