Over 1 Million WordPress Sites at Risk After Popular Plugin Hacked — OptinMonster Among Those Hit in CDN Supply-Chain Attack
Sansec said attackers used stolen CDN credentials to inject malicious JavaScript, affecting at least 1.2 million OptinMonster sites.
10 Articles
10 Articles
SCIENCE & TECH: Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN supply-chain attack
Vulnerability in UpdraftPlus plugin on Awesome Motive’s marketing server enabled CDN compromise and malicious JavaScript injection Malware targeted logged‑in WordPress admins, harvesting tokens and creating rogue accounts for full takeover Site owners urged to check for fake admin accounts (‘developer_api1’, ‘dev_xxxxxx’), hidden backdoor plugins, and rotate credentials/security salts More than a million WordPress websites were at risk of full w…
In a supply chain attack, attackers install backdoors through the WordPress plug-ins OptinMonster, TrustPulse and PushEngage.
OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack
A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec discovered an ongoing campaign targeting plugins developed by Awesome Motive, including OptinMonster, TrustPulse, and PushEngage. These plugins are installe…
OptinMonster WordPress plugin compromised in CDN supply chain attack

Coverage Details
Bias Distribution
- 67% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




