Hundreds of WordPress sites infected by recently discovered backdoor | People who use WordPress should check their sites for unpatched plugins.

TL;DR

The plugins exploited include:- WP Live Chat Support Plugin- WordPress – Yuzo Related Posts- Yellow Pencil Visual Theme Customizer Plugin- Easysmtp- WP GDPR Compliance Plugin- Newspaper Theme on WordPress Access Control (vulnerability CVE-2016-10972)- Thim Core- Google Code Inserter- Total Donations Plugin- Post Custom Templates Lite- WP Quick Booking Manager- Facebook Live Chat by Zotabox- Blog Designer WordPress Plugin- WordPress Ultimate FAQ (vulnerabilities CVE-2019-17232 and CVE-2019-17233)- WP-Matomo Integration (WP-Piwik)- WordPress ND Shortcodes For Visual Composer- WP Live Chat- Coming Soon Page and Maintenance Mode- Hybrid- Brizy WordPress Plugin- FV Flowplayer Video Player- WooCommerce- WordPress Coming Soon Page- WordPress theme OneTone- Simple Fields WordPress Plugin- WordPress Delucks SEO plugin- Poll, Survey, Form & Quiz Maker by OpinionStage- Social Metrics Tracker- WPeMatico RSS Feed Fetcher- Rich Reviews plugin“If one or more vulnerabilities are successfully exploited, the targeted page is injected with a malicious JavaScript that is downloaded from a remote server,” the Dr.Web writeup explained.]comletsmakeparty3[.]gadeliverygoodstrategies[.]comgabriellalovecats[.]comclon[.]collectfasttracks[."

Like summarized versions? Support us on Patreon!