Open Source · · 3 days

Wrapper Link Elementor plugin created backdoors

Malicious code was injected directly into the Wrapper Link Elementor plugin repository on WordPress.org.

Part of WordPress.org plugins created admin backdoors campaign

Wrapper Link Elementor was another official WordPress.org plugin affected in the June 2024 campaign. The malicious code entered the trusted plugin channel, so the package looked like a normal update to site owners.

Wordfence listed versions 1.0.2 and 1.0.3 as infected. It noted that malicious code appeared removed later, but the available tag was 1.0.0, lower than the infected versions, making normal upgrade behavior awkward.

The shared payload attempted administrator account creation, sent the new credentials to 94.156.79.8, and injected SEO-spam JavaScript. That meant a site could be both backdoored and polluted with attacker-controlled footer content after a routine plugin update.

This record keeps the Wrapper Link Elementor version range separate from the other plugin artifacts. The version rollback detail matters because cleanup was not a simple upgrade-to-latest workflow at the time Wordfence published.

Appendix · Affected releases

Indicators

  • file_sha256wrapper-link-elementor-r3106372-wrapper.php 3a1d54c12fb03d67d8143dfe5894dcf10236b288696509fd8e60e22b80bfe883
  • file_sha256wrapper-link-elementor-r3106508-wrapper.php 8808363fd1caa976ee81dae0dc1bcb6b253d11cc355768fa32ef65850f21543c

References

  1. Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
  2. CVE-2024-6297 recordcveawg.mitre.org
  3. Various Plugins - Injected Backdoorwpscan.com

Source record: oss/attacks/wp-wrapper-link-element/meta.yaml