WordPress websites are hacked to hijack your browser and then attack other sites

Cybercriminals are using compromised WordPress websites to create a huge army for credential stuffing attacks, experts warn.

A report from cybersecurity researchers Sucuri has noticed the campaign and thinks they know what its purpose is: namely to look for vulnerable sites of the website builder, where they can install a small script in the HTML templates. That script forces the website visitor’s computer to visit (in the background, unbeknownst to the victim) another WordPress website and attempt to log in with different username and password combinations.