04/17/2026
Urgent issue with 30 Wordpress plugins created by Essential Plugins that were sold and the buyer installed malware into them. I just found out about it from an email from my host, as some of the plugins are VERY common, and it takes more than just removing the plugin, requiring scouring the site for removing any malicious back doors that might have been injected.
Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into