Someone has apparently snaffled up 31 WordPress plugins and wedged a backdoor in each one
An individual reportedly purchased 31 WordPress plugins and inserted backdoors into each one, with the malicious code being activated around April 5, 2026. The incident highlights a vulnerability in WordPress.org's system, which lacks a mechanism to flag or review plugin ownership transfers, potentially leaving users unaware of compromised software.
PC Gamer
- Entities
- Software Supply Chain Attacks
- WordPress
- Cybersecurity
- Plugin Ownership Transfers
- Essential Plugin
Original source
This article was reported and published by PC Gamer. feed.gg links to it as part of a story cluster — full text, images and rights remain with the publisher.