Skip to content

// #website-security

1 article

⚖️ Risk Mgmt

WordPress Redirect Plugin Carried Dormant Backdoor for Three Years Before Activation

Researchers have uncovered a dormant backdoor in a widely-installed WordPress redirect management plugin that remained inactive for approximately three years before being activated by the attackers. The backdoor, present across an estimated 200,000+ active installations, highlights the long-game threat of supply chain compromise in the WordPress plugin ecosystem and the limits of periodic security scanning.

#wordpress +5