Thousands of WordPress websites have been hit by a new malware attack, here’s what we know


  • Security researchers find more than 5,000 websites with a piece of malicious code
  • The malware installs a plugin that steals login credentials and sensitive data
  • The researchers recommended a number of mitigating measures

Thousands of WordPress websites were observed using malware capable of creating a fraudulent administrator account and exfiltrating sensitive data via malicious plugins.

A new one report Security researcher Himanshu Anand of c/side claims that at least 5,000 WordPress websites have been found hosting a malicious script that creates an unauthorized administrator account with a username and password found in the code.