Affected Systems
WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected. Scope includes any WordPress installation with these plugins active during the attack window.
Exploitation Status
Active exploitation confirmed. Attackers successfully injected malicious JavaScript into plugin files served from vendor infrastructure. Backdoors create unauthorized admin accounts and install hidden plugins when legitimate site administrators are logged in.
Business Impact
Critical supply chain compromise affecting potentially thousands of WordPress sites. Attackers gain persistent admin-level access through backdoor accounts and hidden plugins, enabling full site takeover, data exfiltration, malware distribution, and SEO spam injection. Detection is difficult as malicious code executes only when legitimate admins are authenticated. No CVE assigned as this is infrastructure compromise, not software vulnerability. Organizations must assume breach if plugins were active during attack period.
Urgency
🔴 Immediate
Recommended Actions
- Immediately audit all WordPress admin accounts for unauthorized users created recently; remove any unrecognized accounts
- Review installed plugins list for hidden or unfamiliar plugins; check wp-content/plugins directory for unauthorized files
- Disable and remove PushEngage, OptinMonster, and TrustPulse plugins until vendors confirm clean versions are available
- Review web server access logs and WordPress audit logs for suspicious admin activity, plugin installations, or user creation events
- Force password resets for all WordPress administrator accounts and implement multi-factor authentication
- Scan WordPress database for backdoor code in posts, pages, themes, and plugin files using security tools like Wordfence or Sucuri
