Open Source · · 1 day

WordPress.org plugins created admin backdoors

On June 21, 2011, the WordPress team found suspicious unauthorized commits to three popular WordPress.org plugins: AddThis, WPtouch, and W3 Total Cache. The commits contained disguised PHP backdoors and were not made by the legitimate authors.

This incident was not a vulnerable plugin being exploited after release. It was an official repository problem: code shipped from WordPress.org carried commits that the project determined were not made by the plugin authors. That puts it squarely in the supply-chain line, where the distribution path itself hands users the backdoor.

The affected plugins were AddThis, WPtouch, and W3 Total Cache, all common enough that a brief malicious update window mattered. The WordPress team described the changes as disguised backdoors, rolled them back, pushed clean versions, and shut down plugin repository access while checking for anything else suspicious.

The public guidance was practical and terse. Anyone who used those plugins and might have updated during the previous day was told to visit the updates page and install the latest clean versions. WordPress.org also forced password resets across WordPress.org, bbPress.org, and BuddyPress.org because the root cause was still under investigation.

The event belongs next to, but separate from, the 2007 WordPress core archive compromise. In 2007 the official core download was altered; in 2011 the plugin repository carried malicious commits into specific third-party plugin releases. Both are official distribution failures, but the artifact scopes are different.

Appendix · Affected releases

addthis wordpress fixed 2.2.0
2.1.3 sha256 8649455e…751f6f10 download unavailable
wptouch wordpress fixed 1.9.29
1.9.27 no sample yet
1.9.28 sha256 fb6fc8d8…5bb8e30f download unavailable
w3-total-cache wordpress fixed 0.9.2.3
0.9.2.2 sha256 32b3d237…487e0c47 download unavailable

References

  1. Passwords Resetwordpress.org
  2. Malicious software downloads invade WordPresstheregister.com
  3. Add This, W3 Total Cache, WPtouch backdoorsweb.archive.org

Source record: oss/attacks/wordpress-plugin-repository-2011/meta.yaml