Open Source · · 3 days
Wrapper Link Elementor plugin created backdoors
Malicious code was injected directly into the Wrapper Link Elementor plugin repository on WordPress.org.
Part of WordPress.org plugins created admin backdoors campaign
Wrapper Link Elementor was another official WordPress.org plugin affected in the June 2024 campaign. The malicious code entered the trusted plugin channel, so the package looked like a normal update to site owners.
Wordfence listed versions 1.0.2 and 1.0.3 as infected. It noted that malicious code appeared removed later, but the available tag was 1.0.0, lower than the infected versions, making normal upgrade behavior awkward.
The shared payload attempted administrator account creation, sent the new credentials to 94.156.79.8, and injected SEO-spam JavaScript. That meant a site could be both backdoored and polluted with attacker-controlled footer content after a routine plugin update.
This record keeps the Wrapper Link Elementor version range separate from the other plugin artifacts. The version rollback detail matters because cleanup was not a simple upgrade-to-latest workflow at the time Wordfence published.
Appendix · Affected releases
- Immutable SVN revision 3106372 is the first observed malicious source state and declares version 1.0.2. Revision 2847672 is the preceding clean file, revision 3106508 is malicious 1.0.3, and revision 3106777 is clean version 1.0.5.
- Wordfence reported that malicious code appeared removed later, but the latest tag was lower than the infected versions, so removal was recommended until a properly tagged safe release existed.
Indicators
- file_sha256wrapper-link-elementor-r3106372-wrapper.php 3a1d54c12fb03d67d8143dfe5894dcf10236b288696509fd8e60e22b80bfe883
- file_sha256wrapper-link-elementor-r3106508-wrapper.php 8808363fd1caa976ee81dae0dc1bcb6b253d11cc355768fa32ef65850f21543c
References
- Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
- CVE-2024-6297 recordcveawg.mitre.org
- Various Plugins - Injected Backdoorwpscan.com
Source record: oss/attacks/wp-wrapper-link-element/meta.yaml