Plugins on WordPress.org backdoored in supply chain attack
25 juin 2024 à 21:25
A threat actor modified the source code of at least five plugins hosted on WordPress.org to include malicious PHP scripts that create new accounts with administrative privileges on websites running them. [...]