Nearly a million WordPress sites targeted in extensive attacks - Help Net Security

Nearly a million WordPress sites targeted in extensive attacks - Help Net Security

A threat actor is actively trying to insert a backdoor into and compromise WordPress-based sites to redirect visitors to malvertising.



“While our records show that this threat actor may have sent out a smaller volume of attacks in the past, it’s only in the past few days that they’ve truly ramped up, to the point where more than 20 million attacks were attempted against more than half a million individual sites on May 3, 2020,” Wordfence analysts discovered.


“Over the course of the past month in total, we’ve detected over 24,000 distinct IP addresses sending requests matching these attacks to over 900,000 sites.”


About the attacks


The group has an obvious predilection for older cross-site scripting (XSS) and options update vulnerabilities in less popular WordPress plugins and themes such as Easy2Map, Blog Designer, ..

Support the originator by clicking the read the rest link below.