Campaign · Open Source · · 3 days

WordPress.org plugins created admin backdoors

The June 2024 WordPress.org plugin campaign inserted backdoors into several established plugins through the official plugin distribution channel.

Draws together 5 incidents across 5 packages

This campaign compromised WordPress plugins at the source: the official WordPress.org plugin repository. Site owners did not have to install a lookalike plugin or download from a third-party site. Updating a trusted plugin was enough.

Wordfence first saw Social Warfare on June 24, 2024 after a WordPress.org Plugin Review Team forum post, then found four more plugins with similar injected code. The earliest known injection dated to June 21, and the attacker was still making plugin updates hours before Wordfence published. The injected PHP attempted to create new administrator accounts named Options or PluginAuth, then sent the credentials to 94.156.79.8, and the attacker also injected footer JavaScript that added SEO spam across affected sites.

The useful lesson is the distribution boundary. WordPress.org plugin updates are a normal maintenance workflow, so a malicious commit in that channel can reach sites without any phishing, typosquatting, or manual upload by the site owner.

This campaign record carries the shared method and indicators. The individual plugin records carry the package names, affected versions, and specific WordPress.org distribution paths.

Incidents in this campaign

  1. Blaze Widget plugin created backdoors
  2. Contact Form 7 addon created backdoors
  3. Simply Show Hooks plugin created backdoors
  4. Social Warfare plugin created backdoors
  5. Wrapper Link Elementor plugin created backdoors

Appendix · Affected packages

blaze-widget 2024-06-21 to 2024-06-24
2.2.42.5.2
contact-form-7-multi-step-addon 2024-06-21 to 2024-06-24
1.0.41.0.5
simply-show-hooks 2024-06-21 to 2024-06-24
1.2.11.2.2
social-warfare 2024-06-21 to 2024-06-24
4.4.6.44.4.7.1
wrapper-link-elementor 2024-06-21 to 2024-06-24
1.0.21.0.3

Samples and hashes sit on each incident page, linked above

References

  1. Multiple WordPress Plugins Compromised at the Sourcewordfence.com
  2. Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com

Source record: oss/campaigns/wordpress-plugin-backdoor-2024/meta.yaml