Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I Used Instagram Instants Without the Dedicated App And Here’s What Disturbed Me

    May 23, 2026

    Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

    May 22, 2026

    Gemini 3.5 Flash Explained: Everything You Need to Know About Google’s Most Capable Fast Model

    May 21, 2026
    Facebook X (Twitter) Instagram YouTube
    Facebook X (Twitter) Instagram YouTube
    Droid ExposeDroid Expose
    • AI

      Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

      May 22, 2026

      Gemini 3.5 Flash Explained: Everything You Need to Know About Google’s Most Capable Fast Model

      May 21, 2026

      Google I/O 2026: Gemini 3.5 Flash, Our SynthID Experiment and More AI Announcements

      May 21, 2026

      Google Introduces Gemini Omni: A New Era for Conversational Video Editing

      May 20, 2026

      Malta Partners with OpenAI to Provide Free ChatGPT Plus to Every Citizen

      May 17, 2026
    • Software

      I Used Instagram Instants Without the Dedicated App And Here’s What Disturbed Me

      May 23, 2026

      Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

      May 22, 2026

      WhatsApp Is Testing After Reading Disappearing Messages on iPhone

      May 18, 2026

      After 3 Years I Found SimpMusic as a Spotify Alternative — But Here Is the Reality

      May 17, 2026

      Android 17 adds Proactive AI, Quantum Security, and a War on Doomscrolling

      May 14, 2026
    • Features

      Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

      May 22, 2026

      Google I/O 2026: Gemini 3.5 Flash, Our SynthID Experiment and More AI Announcements

      May 21, 2026

      Google Introduces Gemini Omni: A New Era for Conversational Video Editing

      May 20, 2026

      WhatsApp Is Testing After Reading Disappearing Messages on iPhone

      May 18, 2026

      Android 17 adds Proactive AI, Quantum Security, and a War on Doomscrolling

      May 14, 2026
    • Security

      WhatsApp Is Testing After Reading Disappearing Messages on iPhone

      May 18, 2026

      After 3 Years I Found SimpMusic as a Spotify Alternative — But Here Is the Reality

      May 17, 2026

      Android and iPhone Users Finally Get End-to-End Encrypted RCS Messaging

      May 12, 2026

      Meta Ends End-to-End Encryption for Instagram DMs

      May 9, 2026

      Meta’s New AI Scans Bone Structure to Spot Underage Users

      May 5, 2026
    • News

      Google I/O 2026: Gemini 3.5 Flash, Our SynthID Experiment and More AI Announcements

      May 21, 2026

      Malta Partners with OpenAI to Provide Free ChatGPT Plus to Every Citizen

      May 17, 2026

      Google might drop your free 15GB storage to 5GB if you aren’t verified

      May 15, 2026

      Realme 16T 5G Confirmed: The 8,000mAh Powerhouse

      May 12, 2026

      Alibaba to Launch AI-Powered Agentic Shopping via Qwen and Taobao Integration

      May 11, 2026
    Droid ExposeDroid Expose
    Home - 31 WordPress Plugins Banned After Discovery of Secret Backdoor
    Security

    31 WordPress Plugins Banned After Discovery of Secret Backdoor

    Tawsif RezaBy Tawsif RezaApril 20, 2026Updated:May 19, 2026No Comments3 Mins Read
    Facebook Twitter Email WhatsApp Copy Link
    WordPress backdoor
    Share
    Facebook Twitter LinkedIn Email WhatsApp Copy Link

    Our editorial team is comprised of skilled technology experts and developers. To ensure that our research is easy to understand in simple and plain English, we may use AI-assisted tools for grammatical refinement and structural smoothness. However, every technical insight, test, and experience displayed has been fully completed and verified by our human team. All content remains the original property of Droid Expose. See more in our Privacy Policy.

    The WordPress.org security team took the unprecedented step last week of permanently banning every plugin associated with the Essential Plugin developer account. The move follows a detailed forensic report by Austin Ginder, founder of Anchor Hosting, who discovered that the plugins were being used to inject spam and malicious redirects into thousands of websites.

    The attack was not a traditional hack. Instead, it was a “supply-chain” strike that began when the original owners of the plugin portfolio sold their business on a public marketplace.

    Table of Contents

    • The 8-Month Sleep
    • A Highly Sophisticated Attack
    • Is Your Site at Risk?
    • Recommendations for Site Owners
    • The Trust Problem in WordPress

    The 8-Month Sleep

    According to Ginder’s investigation, the backdoor was planted as far back as August 2025, shortly after a new buyer—identified only by the alias “Kris”—acquired the portfolio for a six-figure sum. The attacker intentionally kept the malicious code dormant for eight months to evade detection by security scanners.

    The weaponization finally began on April 5, 2026. The dormant code “phoned home” to a remote server, which then pushed a massive block of malicious PHP into the victim sites’ wp-config.php files. This allowed the attacker to display fake pages and spam links specifically to Googlebot, effectively hijacking the site’s SEO while remaining invisible to the actual website owners.

    A Highly Sophisticated Attack

    What makes this breach particularly alarming to security professionals is the level of technical sophistication involved. The attacker used an Ethereum smart contract to manage their command-and-control servers. Because the server addresses are stored on the blockchain, traditional domain takedowns are ineffective—the attacker can simply update the smart contract to point to a new server at any time.

    Is Your Site at Risk?

    The affected plugins cover a wide range of functions, from “Countdown Timer Ultimate” to “Popup Anything on Click” and “WP Team Showcase.” While WordPress has forced an automatic update to neutralize the “phone-home” mechanism, experts warn that this is only a temporary fix.

    According to security audits, the forced update does not clean the infected wp-config.php files. If your site was running one of these plugins between April 5 and April 7, it may still be serving hidden spam to search engines.

    Recommendations for Site Owners

    If you have any plugins from the “Essential Plugin” or “WP Online Support” brand installed, security experts recommend taking the following steps immediately:

    1. Delete the Plugin: Since these are now permanently closed on WordPress.org, they will no longer receive security updates.
    2. Audit your wp-config.php: Check the end of the file for any unusual code, especially if the file size has suddenly increased by about 6KB.
    3. Run a Full Security Scan: Use tools like Wordfence or Sucuri to ensure no secondary backdoors were left behind.

    You may also like to read: Google Announces Search Ban for Websites Using Back Button Hijacking

    The Trust Problem in WordPress

    This incident has reignited a debate about security within the WordPress plugin repository. Currently, WordPress does not notify users when a plugin changes ownership, making it easy for malicious actors to purchase established tools and “inherit” the trust of thousands of unsuspecting users.

    Austin Ginder case study supply chain attack Wordpress news Wordpress plugin banned Wordpress security
    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Articles

    I Used Instagram Instants Without the Dedicated App And Here’s What Disturbed Me

    May 23, 2026

    Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

    May 22, 2026

    Google I/O 2026: Gemini 3.5 Flash, Our SynthID Experiment and More AI Announcements

    May 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Droid Selections

    Meta’s New AI Scans Bone Structure to Spot Underage Users

    May 5, 2026

    Windows 11 Now Includes a Console Style Xbox Mode

    May 1, 2026

    YouTube to Pause Ads During Peak Livestream Moments to Protect the Vibe

    April 19, 2026

    Google Retires Fitbit App for New Google Health Hub and AI Coach

    May 8, 2026
    Our Reviews

    I Used Instagram Instants Without the Dedicated App And Here’s What Disturbed Me

    By Tawsif Reza

    After 3 Years I Found SimpMusic as a Spotify Alternative — But Here Is the Reality

    By Tawsif Reza

    Case Study: Is AI Really Helping Criminals?

    By Tawsif Reza
    Droid Expose
    Facebook X (Twitter) Instagram Pinterest YouTube Telegram
    • About Us
    • Contact Us
    • Terms Of Use
    • Editorial Policy
    • Privacy Policy
    © 2026 Droid Expose. Powered by Droid Expose.

    Type above and press Enter to search. Press Esc to cancel.