Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Dozens of WordPress plug-ins removed after backdoor discovered

The affected plug-ins have been removed from WordPress' directory and their closure is being labeled as "permanent."

byKerem Gülen
April 15, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Dozens of WordPress plug-ins went offline following the discovery of a backdoor that delivered malicious code to users. The issue arose after the corporate acquisition of the plug-in maker Essential Plugin, prompting security concerns.

Austin Ginder, founder of Anchor Hosting, detailed the supply chain attack in a blog post. He stated that a backdoor was added to the plug-ins’ source code soon after last year’s acquisition. This backdoor remained inactive until earlier this month when it began distributing malicious code to websites utilizing the affected plug-ins.

Essential Plugin claims over 400,000 plug-in installs and more than 15,000 customers, while the affected plug-ins have been installed on more than 20,000 active WordPress installations, according to WordPress’ plug-in install page. Although plug-ins enhance the functionality of WordPress websites, they also pose a security risk by allowing access to installations, potentially leading to breaches.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Ginder emphasized that WordPress users lack notifications regarding changes in plug-in ownership, which increases the risk of takeover attacks. According to him, this incident marks the second hijacking of a WordPress plug-in in two weeks. Security researchers have expressed concerns about the dangers posed by malicious actors acquiring software to alter its code for widespread compromise.

The affected plug-ins have been removed from WordPress’ directory and their closure is being labeled as “permanent.” Ginder urged WordPress site owners to verify and remove any remaining malicious plug-ins installed on their websites. A list of these plug-ins is available in his blog post. Essential Plugin representatives did not respond to a request for comment.


Featured image credit

Tags: wordpress

Related Posts

Steam Next Fest sees one in five demos labeled for generative AI

Steam Next Fest sees one in five demos labeled for generative AI

June 17, 2026
Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

June 17, 2026
Roblox expands age-based account tiers worldwide with new parental controls

Roblox expands age-based account tiers worldwide with new parental controls

June 17, 2026
Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

June 17, 2026
Is Gemini down? Users report problems with Google Gemini

Is Gemini down? Users report problems with Google Gemini

June 17, 2026
Google releases Android 17

Google releases Android 17

June 17, 2026

LATEST NEWS

Steam Next Fest sees one in five demos labeled for generative AI

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Roblox expands age-based account tiers worldwide with new parental controls

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Is Gemini down? Users report problems with Google Gemini

Google releases Android 17

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Wiz Write

BoldVoice

Bith

Concisely

YourGPT

Sonoteller

RoomGPT

Rosie

LedgerUp

Call Annie

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.