WordPress plugin hijack plants hidden backdoors

Attackers tampered with JavaScript served by three widely used WordPress marketing plugins, exposing more than 1.2 million websites to rogue administrator accounts and concealed backdoors.

The incident affected OptinMonster, TrustPulse and PushEngage, products operated under the Awesome Motive umbrella and embedded on sites for pop-ups, lead generation, social proof alerts and push notifications. The compromise did not arrive through a normal plugin update. Instead, malicious code was appended to legitimate front-end scripts delivered through vendor-controlled content delivery network endpoints, meaning fully patched websites could still have loaded the poisoned files.

The injected script was designed to stay quiet for ordinary visitors. It activated only when a logged-in WordPress administrator loaded an affected page, then used that session to collect valid security tokens and make requests that looked like legitimate administrative actions. Once triggered, it attempted to create a new administrator account, install a self-hiding plugin and transmit credentials and site details to an attacker-controlled lookalike domain, tidio. cc, which mimicked the legitimate tidio. com brand.

The fixed operator account identified in the campaign was developerapi1 using the email customer1usx@gmail. com, while most observed attempts used randomised devxxxxxx administrator identities. The backdoor plugin rotated names, including “Content Delivery Helper” and “Database Optimizer”, and was built to hide from plugin lists, user lists, update checks and common dashboard views. It also exposed a web shell capable of running server commands and a separate code-execution endpoint.

The exposure window varied across products. Malicious code was seen in OptinMonster and TrustPulse script files late on June 12 UTC and was removed within a short window, while PushEngage’s affected scripts were served for several hours on June 12 and continued from some CDN edge locations into June 14. The companies have since said the altered files were removed, CDN caches purged and credentials rotated, but those steps do not remove backdoors already planted on customer websites.

OptinMonster has more than 1 million active WordPress installations, while PushEngage lists more than 9,000 active installations. OptinMonster’s own marketing says more than 1.2 million users rely on the service. WordPress remains the dominant content management system, powering about 41.5 per cent of all websites and 59.3 per cent of sites whose content management system can be identified, making plugin supply-chain incidents unusually wide in reach.

Vendor notices attributed the breach to an attacker gaining access to a marketing website server through a known vulnerability in UpdraftPlus, a backup and migration plugin, and then finding a CDN API key on that server. They said application servers, source code repositories and customer-data systems were hosted separately and showed no evidence of access. Security researchers have treated the initial entry point as still needing full corroboration, while agreeing that the critical abuse path was control over scripts delivered from trusted CDN locations.

The UpdraftPlus issue cited in the notices is tracked as CVE-2026-10795 and affects versions up to and including 1.26.4 in specific circumstances involving UpdraftCentral connections. It allows unauthenticated attackers to run remote procedure calls as a connected administrator, potentially uploading and activating malicious plugins. The flaw has been patched, but its appearance in the same chronology highlights the layered risk created when a plugin, a marketing site and a CDN key intersect.

Firewall telemetry from protected sites showed 271 blocked exploitation attempts across 13 websites over about 36 hours on June 14 and 15, from 81 unique IP addresses. Most attempts used the WordPress REST users endpoint, matching the payload’s effort to create an administrator account under cover of a genuine admin session.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // What Shein’s $27bn IPO means for Mubadala // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Dubai hotel provides free public co-working space // Apple raises evidence-destruction claims against OpenAI // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Russia brings cryptocurrency market law into force // India plans own orbital space outpost, second after China // Haldwani purification row: Caste back on political centre-stage // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Trump rejects munitions fears as Iran clashes resume //