Tech

A key WordPress feature has been hijacked to show malicious code, spam images

Share
Share


  • Researchers from Sucuri found malicious code hiding in the mu-plugins directory
  • The malware redirected visitors, served spam, and could even drop malware
  • The sites were compromised through vulnerable plugins, poor admin passwords, and more

A special directory in WordPress is being abused to host malicious code, researchers has claimed, warning the code allows threat actors to remain persistent on vulnerable websites, while executing arbitrary code, redirecting people to malicious websites, and displaying unwanted spam and ads.

Researchers from Sucuri discovered threat actors were hiding malicious code in “mu-plugins” (short for Must-Use plugins), a directory that stores plugins that are activated automatically and cannot be deactivated through the admin panel.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Microsoft 365 launches an on-premise edition that wants to solve productivity issues for good
Tech

Microsoft 365 launches an on-premise edition that wants to solve productivity issues for good

Microsoft 365 Local is an entirely on-prem solution for data sovereignty requirements...

Baltimore lawyer sues Meta, Google over online ‘squatter house’ networks
Tech

Baltimore lawyer sues Meta, Google over online ‘squatter house’ networks

Credit: Pixabay/CC0 Public Domain In his second lawsuit targeting social media giants,...

California’s ‘No Robo Bosses Act’ advances, taking aim at AI in the workplace
Tech

California’s ‘No Robo Bosses Act’ advances, taking aim at AI in the workplace

Credit: Unsplash/CC0 Public Domain One company offers Bay Area employers artificial intelligence...

Intel set for huge factory job cuts as it makes a major policy shift
Tech

Intel set for huge factory job cuts as it makes a major policy shift

Intel reportedly planning to cut 15-20% of factory workers next month News...