Skip to content
Supply Chain Attack Compromises Popular WordPress Plugins Affecting 1.2 Million Sites

Supply Chain Attack Compromises Popular WordPress Plugins Affecting 1.2 Million Sites

First seen 15 Jun 2026, 17:38 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 16, 2026 at 17:12 UTC
  • Malicious JavaScript was served to over 1.2 million sites via Awesome Motive's CDN.
  • The attack exploited a vulnerability in the UpdraftPlus plugin to gain access to CDN credentials.
  • Affected sites should be treated as compromised if an admin was logged in during the attack window.

A supply chain attack has compromised the OptinMonster, TrustPulse, and PushEngage WordPress plugins, impacting over 1.2 million sites. Attackers exploited a known vulnerability in the UpdraftPlus plugin to gain access to Awesome Motive's CDN, allowing them to serve malicious JavaScript directly to customer sites. The malware activates when a logged-in administrator visits an infected site, creating a rogue admin account and installing a hidden backdoor plugin. This backdoor can execute arbitrary PHP code and communicate with a lookalike domain of Tidio. The attack was discovered by Sansec and occurred on June 12, 2026. Awesome Motive has since remediated the issue and rotated all credentials, but affected site owners are advised to treat their sites as compromised.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2026-06-12
Malicious scripts served via Awesome Motive CDN
Attackers delivered tampered JavaScript to customer sites during a brief exposure window, impacting OptinMonster and TrustPulse plugins.
Bleepingcomputer
2026-06-13
Sansec discovers the supply chain attack
E-commerce security firm Sansec identified the ongoing attack affecting multiple WordPress plugins, confirming the malicious payload's activation method.
Sansec
2026-06-15
Awesome Motive issues security advisory
Awesome Motive published a notice detailing the attack, confirming no access to customer data and outlining remediation steps for affected site owners.
Optinmonster

More articles in this cluster (11)

Following this threat?

Track Content Delivery Helper and Awesome Motive in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed