Five Eyes security agencies warn: an active campaign scans the internet for WordPress sites with vulnerable plugins and installs webshells that give attackers full control.
This isn’t a single breach but a wave that mass-exploits already-known vulnerabilities in popular plugins — forms, cache, backup, booking systems. Once compromised, a site can host scams, leak data or become an entry point into the rest of the network. Small businesses are already among the targets.
- Update WordPress and all plugins — patches for these vulnerabilities already exist.
- Delete plugins you no longer use; every inactive plugin is an open door.
- Make sure you have a recent, working backup so you can restore cleanly if needed.
Sources
This article was generated with AI assistance.