FeedApplication SecurityOptinMonster WordPress plugin hacked in CDN supply-chain att...
Application SecurityBleeping Computer
9.0CRITICAL

OptinMonster WordPress plugin hacked in CDN supply-chain attack

📅 15 June 2026 at 17:37 UTC📰 Bleeping ComputerView original source ↗
OptinMonster WordPress plugin hacked in CDN supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A supply-chain attack compromised the OptinMonster and TrustPulse WordPress plugins, allowing attackers to create rogue administrator accounts, install backdoor plugins, and gain full remote access to infected websites.

⚙️Technical Details
Affected Systems
OptinMonsterTrustPulseAwesome Motive's content distribution network (CDN)
Attack Vectors
Exploitation of a known flaw in the UpdraftPlus WordPress pluginMalicious scripts served via Awesome Motive's CDN
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Check for, and remove rogue admin accounts 'developer_api1' or 'dev_xxxxxx'
2Inspect the filesystem directly under wp-content/plugins for hidden backdoor plugins
3Rotate administrator passwords, API keys, database credentials, and WordPress security salts
📦Affected Products
OptinMonsterTrustPulse

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed