Infosecurity-Magazine
Supply Chain Attack Compromises Popular WordPress Plugins Affecting 1.2 Million Sites
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A supply chain attack has compromised the OptinMonster, TrustPulse, and PushEngage WordPress plugins, impacting over 1.2 million sites. Attackers exploited a known vulnerability in the UpdraftPlus plugin to gain access to Awesome Motive's CDN, allowing them to serve malicious JavaScript directly to customer sites. The malware activates when a logged-in administrator visits an infected site, creating a rogue admin account and installing a hidden backdoor plugin. This backdoor can execute arbitrary PHP code and communicate with a lookalike domain of Tidio. The attack was discovered by Sansec and occurred on June 12, 2026. Awesome Motive has since remediated the issue and rotated all credentials, but affected site owners are advised to treat their sites as compromised.
Key Points: • Malicious JavaScript was served to over 1.2 million sites via Awesome Motive's CDN. • The attack exploited a vulnerability in the UpdraftPlus plugin to gain access to CDN credentials. • Affected sites should be treated as compromised if an admin was logged in during the attack window.