Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers https://t.co/a09xIuWfms
Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers: https://t.co/fVhQ8m57WY by The Hacker News #infosec #cybersecurity #technology #news
🛑 Hackers are disguising malware as security plugins to hijack sites, inject spammy ads, steal credit cards, & even re-install themselves if deleted. Some victims are unknowingly losing their own AdSense earnings. 💣 Features: Remote code execution, reverse proxy skimming, https://t.co/6itlXmnptH
A new malware threat has been identified targeting WordPress websites through a fake security plugin that grants attackers remote administrative access. This malicious plugin, disguised as an anti-malware tool, injects a backdoor into affected sites, enabling hackers to execute remote code, hijack websites, inject spam advertisements, steal credit card information, and even reinstall themselves if removed. Some victims have reported losing their own AdSense earnings as a result of this compromise. Cybersecurity experts have raised concerns about the growing use of such deceptive plugins to exploit WordPress platforms.