Hackers are using a recently tracked WordPress
flaw
to breach thousands of websites.
The flaw has been active for the last 11 years.
- The malware, which is programmed in PHP, is spread via an infected plugin.
- The number of websites that had downloaded the plugin reached 6,988 by March 30, 2023, while it has been downloaded over 23,110 times in the last week alone.
- Researchers stated that they've detected over 6,000 instances of this backdoor on compromised websites in the last six months, describing the pattern of inserting the malware directly into the database.
-
Only a few weeks ago, a security flaw enabled hackers to
infect
over 1 million WordPress websites.
-
According to researchers, at least 13,000 WordPress websites are
hacked
every day.