Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site Images

The Hacker News by The Hacker News
March 31, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Mar 31, 2025Ravie LakshmananData Theft / Website Security

Threat actors are using the “mu-plugins” directory in WordPress sites to conceal malicious code with the goal of maintaining persistent remote access and redirecting site visitors to bogus sites.

mu-plugins, short for must-use plugins, refers to plugins in a special directory (“wp-content/mu-plugins”) that are automatically executed by WordPress without the need to enable them explicitly via the admin dashboard. This also makes the directory an ideal location for staging malware.

“This approach represents a concerning trend, as the mu-plugins (Must-Use plugins) are not listed in the standard WordPress plugin interface, making them less noticeable and easier for users to ignore during routine security checks,” Sucuri researcher Puja Srivastava said in an analysis.

Cybersecurity

In the incidents analyzed by the website security company, three different kinds of rogue PHP code have been discovered in the directory –

  • “wp-content/mu-plugins/redirect.php,” which redirects site visitors to an external malicious website
  • “wp-content/mu-plugins/index.php,” which offers web shell-like functionality, letting attackers execute arbitrary code by downloading a remote PHP script hosted on GitHub
  • “wp-content/mu-plugins/custom-js-loader.php,” which injects unwanted spam onto the infected website, likely with an intent to promote scams or manipulate SEO rankings, by replacing all images on the site with explicit content and hijacking outbound links to malicious sites

The “redirect.php,” Sucuri said, masquerades as a web browser update to deceive victims into installing malware that can steal data or drop additional payloads.

“The script includes a function that identifies whether the current visitor is a bot,” Srivastava explained. “This allows the script to exclude search engine crawlers and prevent them from detecting the redirection behavior.”

The development comes as threat actors are continuing to use infected WordPress sites as staging grounds to trick website visitors into running malicious PowerShell commands on their Windows computers under the guise of a Google reCAPTCHA or Cloudflare CAPTCHA verification – a prevalent tactic called ClickFix – and deliver the Lumma Stealer malware.

Hackers Exploit WordPress

Hacked WordPress sites are also being used to deploy malicious JavaScript that can redirect visitors to unwanted third-party domains or act as a skimmer to siphon financial information entered on checkout pages.

It’s currently not known how the sites may have been breached, but the usual suspects are vulnerable plugins or themes, compromised admin credentials, and server misconfigurations.

Cybersecurity

According to a new report from Patchstack, threat actors have routinely exploited four different security vulnerabilities since the start of the year –

  • CVE-2024-27956 (CVSS score: 9.9) – An unauthenticated arbitrary SQL execution vulnerability in WordPress Automatic Plugin – AI content generator and auto poster plugin
  • CVE- 2024-25600 (CVSS score: 10.0) – An unauthenticated remote code execution vulnerability in Bricks theme
  • CVE-2024-8353 (CVSS score: 10.0) – An unauthenticated PHP object injection to remote code execution vulnerability in GiveWP plugin
  • CVE-2024-4345 (CVSS score: 10.0) – An unauthenticated arbitrary file upload vulnerability in Startklar Elementor Addons for WordPress

To mitigate the risks posed by these threats, it’s essential that WordPress site owners keep plugins and themes up to date, routinely audit code for the presence of malware, enforce strong passwords, and deploy a web application firewall to malicious requests and prevent code injections.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Stocks making the biggest moves premarket: Tesla, Stellantis, Nvidia and more

Stocks making the biggest moves premarket: Tesla, Stellantis, Nvidia and more

Recommended.

Stocks making the biggest moves after hours: Palantir Technologies, Ford Motor, Mattel, Clorox and more

Stocks making the biggest moves after hours: Palantir Technologies, Ford Motor, Mattel, Clorox and more

May 5, 2025
ÜBERLEBE GEMEINSAM IN EINER NEUEN TEAM-CHALLENGE VON ZERO LATENCY VR, IN WARHAMMER 40.000 SPACE MARINE VR – THREAT: LETHAL

ÜBERLEBE GEMEINSAM IN EINER NEUEN TEAM-CHALLENGE VON ZERO LATENCY VR, IN WARHAMMER 40.000 SPACE MARINE VR – THREAT: LETHAL

March 8, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio