{"id":18476,"date":"2018-11-09T20:53:41","date_gmt":"2018-11-09T20:53:41","guid":{"rendered":"http:\/\/26def469-92cc-45fc-8fb8-8ce7a75c6987"},"modified":"2018-11-09T20:53:41","modified_gmt":"2018-11-09T20:53:41","slug":"zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/","title":{"rendered":"Zero-day in popular WordPress plugin exploited in the wild to take over sites"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2018\/11\/09\/9bf4d5ad-3a15-4f03-bc75-cf3de0541d5e\/083625468d34af0b7ada51c3e964d691\/wp-gdpr-plugin.png\" class=\"\" alt=\"wp-gdpr-plugin.png\"\/><\/span><\/p>\n<p>Hackers have exploited &#8211;and are currently continuing to exploit&#8211; a now-patched zero-day vulnerability in a popular WordPress plugin to install backdoors and take over sites.<\/p>\n<p>The vulnerability affects <a href=\"https:\/\/wordpress.org\/plugins\/wp-gdpr-compliance\/\" target=\"_blank\" rel=\"noopener noreferrer\">WP GDPR Compliance<\/a>, a WordPress plugin that helps site owners become GDPR compliant. The plugin is one of the most popular GDPR-themed plugins on the WordPress Plugins directory, with over 100,000 active installs.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">More security news<\/span><\/h3>\n<\/div>\n<p>Around three weeks ago, attackers seem to have discovered a vulnerability in this plugin and began using it to gain access to WordPress sites and install backdoor scripts.<\/p>\n<p><a href=\"https:\/\/wordpress.org\/support\/topic\/plugin-installed-itself-and-activated-itself-on-my-site\/\" target=\"_blank\" rel=\"noopener noreferrer\">Initial reports<\/a> about hacked sites were made into another plugin&#8217;s support forum, but that plugin turned out to have been installed as a second-stage payload on some of the hacked sites.<\/p>\n<p>After investigations led by the WordPress security team, the source of the hacks was eventually traced back to WP GDPR Compliance, which was the common plugin installed on all reported compromised sites.<\/p>\n<p>The WordPress team removed the plugin from the official Plugins directory earlier this week after they identified several security issues within its code, which they believed were the cause of the reported hacks.<\/p>\n<p>The plugin was reinstated two days ago, but only after its authors <a href=\"https:\/\/www.wpgdprc.com\/wp-gdpr-compliance-1-4-3-security-release\/\" target=\"_blank\" rel=\"noopener noreferrer\">released version 1.4.3<\/a>, which contained patches for the reported issues.<\/p>\n<h3>Attacks are still going on<\/h3>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>But despite the fixes, attacks on sites still running versions 1.4.2 and older are still going on, according to security experts <a href=\"https:\/\/www.wordfence.com\/blog\/2018\/11\/trends-following-vulnerability-in-wp-gdpr-compliance-plugin\/\" target=\"_blank\" rel=\"noopener noreferrer\">from Defiant<\/a>, a company that runs the Wordfence firewall plugin for WordPress sites.<\/p>\n<p>The company&#8217;s analysts say they&#8217;re continuing to detect attacks that try to exploit one of the reported WP GDPR Compliance security issues.<\/p>\n<p>In particular, attackers are targeting a WP GDPR Compliance bug that allows them to make a call to one of the plugin&#8217;s internal functions and change settings for both the plugin, but also for the entire WordPress CMS.<\/p>\n<p>The Wordfence team says they&#8217;ve seen two types of attacks using this bug. The first scenario goes like this:<\/p>\n<ul>\n<li>Hackers use bug to open the site&#8217;s user registration system.<\/li>\n<li>Hackers use bug to set the default role for new accounts to &#8220;administrator.&#8221;<\/li>\n<li>Hackers register a new account, which automatically becomes an administrator. This new account is usually named &#8220;t2trollherten.&#8221;<\/li>\n<li>Hackers set back default user role for new accounts to &#8220;subscriber.&#8221;<\/li>\n<li>Hackers disable public user registration.<\/li>\n<li>Hackers log into their new admin account.<\/li>\n<li>They then proceed to install a backdoor on the site, as a file named wp-cache.php.<\/li>\n<\/ul>\n<p>This backdoor script (GUI pictured below) contains a file manager, terminal emulator, and a PHP eval() function runner, and Wordfence says that &#8220;a script like this on a site can allow an attacker to deploy further payloads at will.&#8221;<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/\" class=\"lazy\" alt=\"wp-gdpr-plugin-backdoor.png\" data-original=\" https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2018\/11\/09\/ee49b982-decc-4aff-9707-aa3bc57d1cc4\/4ebe58c405a9a480d732a3d65b7860aa\/wp-gdpr-plugin-backdoor.png\"\/><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2018\/11\/09\/ee49b982-decc-4aff-9707-aa3bc57d1cc4\/4ebe58c405a9a480d732a3d65b7860aa\/wp-gdpr-plugin-backdoor.png\" class=\"\" alt=\"wp-gdpr-plugin-backdoor.png\"\/><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Defiant<\/span><\/p>\n<p>But experts also detected a second type of attack, which doesn&#8217;t rely on creating a new admin account, which might be spotted by the hacked site&#8217;s owners.<\/p>\n<p>This second and supposedly more silent technique involves using the WP GDPR Compliance bug to add a new task to WP-Cron, WordPress&#8217; built-in task scheduler.<\/p>\n<p>The hackers&#8217; cron job downloads and installs the 2MB Autocode plugin, which attackers later use to upload another backdoor script on the site &#8211;also named wp-cache.php, but different from the one detailed above.<\/p>\n<p>But while hackers tried to make this second exploitation scenario more silent than the first, it was, in fact, this technique that led to the zero-day&#8217;s discovery.<\/p>\n<p>This happened because, on some sites, the hackers&#8217; exploitation routine failed to delete the 2MB Autocode plugin. Site owners saw a new plugin appeared on their sites and panicked.<\/p>\n<p>It was, in fact, on this plugin&#8217;s WordPress support forum that site owners first complained about hacked sites, and triggered the investigation that led back to the WP GDPR Compliance plugin.<\/p>\n<h3>Attackers are stockpiling hacked sites<\/h3>\n<p>Right now, the attackers don&#8217;t appear to be doing anything malicious with the hacked sites, according to the Wordfence team.<\/p>\n<p>Hackers are just stockpiling hacked sites, and Wordfence has not seen them trying to deploy anything malicious through the backdoor scripts, such as SEO spam, exploit kits, malware, or other kinds of badness.<\/p>\n<p>Site owners using the WP GDPR Compliance plugin still have time to update or remove the plugin from their sites and clean any backdoors that have been left behind. They should do this before their site takes a hit in terms of search engine rankings, which usually happens after Google finds malware on their domains during its regular scans.<\/p>\n<h3>More security coverage:<\/h3>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attacks started around three weeks ago and are still going on. Users should update the WP GDPR Compliance plugin to version 1.4.3 to protect their sites.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":18477,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-18476","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-09T20:53:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"484\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Zero-day in popular WordPress plugin exploited in the wild to take over sites\",\"datePublished\":\"2018-11-09T20:53:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/\"},\"wordCount\":766,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/\",\"name\":\"Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png\",\"datePublished\":\"2018-11-09T20:53:41+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png\",\"width\":1000,\"height\":484},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Zero-day in popular WordPress plugin exploited in the wild to take over sites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/","og_locale":"en_US","og_type":"article","og_title":"Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-11-09T20:53:41+00:00","og_image":[{"width":1000,"height":484,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Zero-day in popular WordPress plugin exploited in the wild to take over sites","datePublished":"2018-11-09T20:53:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/"},"wordCount":766,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/","url":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/","name":"Zero-day in popular WordPress plugin exploited in the wild to take over sites 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png","datePublished":"2018-11-09T20:53:41+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites.png","width":1000,"height":484},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Zero-day in popular WordPress plugin exploited in the wild to take over sites"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/18476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=18476"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/18476\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/18477"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=18476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=18476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=18476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}