Monday, August 3, 2026

Apps & Consumer

Backdoors found in dozens of WordPress plugins

Dozens of WordPress plugins were compromised with backdoors after a corporate acquisition, affecting over 20,000 active installations around the world.

Backdoors found in dozens of WordPress plugins

A supply chain attack has compromised Essential Plugin, a developer of software components that add specific features to WordPress websites. According to Austin Ginder, the founder of Anchor Hosting, someone planted backdoors in dozens of WordPress plug-ins after a new corporate owner purchased Essential Plugin. Ginder published a blog post last week describing the supply chain attack on the WordPress plug-in maker, noting that someone bought Essential Plugin last year and the backdoor was soon added to the plug-ins’ source code. The backdoor sat dormant until earlier this month when it activated and began distributing malicious code to any website that relied on the plug-ins. According to the WordPress plug-in install page, the affected plug-ins are in over 20,000 active WordPress installations.

Plug-ins allow owners of WordPress-based websites to extend their site’s functionality, but doing so grants the software access to their installations. This access can open websites to malicious extensions and potential compromise. Ginder warned that WordPress users are not notified when a plugin changes ownership, which exposes them to potential takeover attacks by their new owners. According to Ginder, this is the second hijack of a WordPress plug-in discovered in as many weeks. Security researchers have long warned of the risks of malicious actors buying software and changing its code in order to compromise a large number of computers around the world.

The scale of the risk is substantial given the reach of the affected developer. Essential Plugin claims on its website that it has over 400,000 plug-in installs and more than 15,000 customers. While the affected plug-ins have been removed from the WordPress directory and now list their closure as permanent, Ginder warned that WordPress owners should check if they still have one of the malicious plug-ins installed and remove it. Ginder has published a list of the affected plug-ins in his blog post to help administrators identify them. Representatives for Essential Plugin did not respond to a request for comment regarding the incident.

Why it matters

The incident highlights a critical supply chain vulnerability where malicious actors purchase legitimate plugins to inject backdoors, exposing thousands of websites to potential takeover attacks without user notification.