PCPC Gamer
Someone has apparently snaffled up 31 WordPress plugins and wedged a backdoor in each one
An individual reportedly purchased 31 WordPress plugins and inserted backdoors into each one, with the malicious code being activated around April 5, 2026. The incident highlights a vulnerability in WordPress.org's system, which lacks a mechanism to flag or review plugin ownership transfers, potentially leaving users unaware of compromised software.