Application SecurityBleeping Computer
9.0 — CRITICAL
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A supply-chain attack compromised the OptinMonster and TrustPulse WordPress plugins, allowing attackers to create rogue administrator accounts, install backdoor plugins, and gain full remote access to infected websites.
⚙️Technical Details
Affected Systems
OptinMonsterTrustPulseAwesome Motive's content distribution network (CDN)
Attack Vectors
Exploitation of a known flaw in the UpdraftPlus WordPress pluginMalicious scripts served via Awesome Motive's CDN
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Check for, and remove rogue admin accounts 'developer_api1' or 'dev_xxxxxx'
2Inspect the filesystem directly under wp-content/plugins for hidden backdoor plugins
3Rotate administrator passwords, API keys, database credentials, and WordPress security salts
📦Affected Products
OptinMonsterTrustPulse
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
