Several WordPress.org Plugins <= Various Versions - Injected Backdoor
Affected versions: 1.5.4; 1.6.2; 1.6.3; 2.1.2; 11.9.3-11.9.4; 1.3.15; 1.3.16; 4.4.6.4-4.4.7.1
Vulnerability type: CWE-506 Embedded Malicious Code
Affected software, patched versions and attribution
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. All plugins have received updates reverting any added malicious code. Simply Show Hooks affected version (1.2.1) is the same as the patched version (1.2.1) - it does not appear that the malicious copy was ever officially released, so sites running 1.2.1 should be unaffected, though it is a good idea to run a complete Wordfence scan and verify that there are no rogue administrator accounts present.
Twenty20 Image Before-After
Affected versions: 1.5.4; 1.6.2; 1.6.3
Patched versions: 1.6.4
Seo Optimized Images
Affected versions: 2.1.2
Patched versions: 2.1.4
PowerPress Podcasting plugin by Blubrry
Affected versions: 11.9.3-11.9.4
Patched versions: 11.9.6
WPCOM Member
Affected versions: 1.3.15; 1.3.16
Patched versions: 1.3.14
Social Sharing Plugin – Social Warfare
Affected versions: 4.4.6.4-4.4.7.1
Patched versions: 4.4.7.3
Contact Form Multi-Step Addon
Affected versions: 1.0.4-1.0.5
Patched versions: 1.0.7
Simply Show Hooks
Affected versions: 1.2.1-1.2.2
Patched versions: 1.2.1
Britetechs Companion
Affected versions: 2.2.7
Patched versions: 2.2.8
Wrapper Link Elementor
Affected versions: 1.0.2-1.0.3
Patched versions: 1.0.5
Ad Invalid Click Protector (AICP)
Affected versions: 1.2.9
Patched versions: 1.2.11
BLAZE Retail Widget
Affected versions: 2.2.5-2.5.2
Patched versions: 2.5.4
Pods – Custom Content Types and Fields
Affected versions: 3.2.3
Patched versions: 3.2.4
WP Server Health Stats
Affected versions: 1.7.6
Patched versions: 1.7.8
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
This record contains material that is subject to copyright
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
- Published
- June 24, 2024
- CVSS
- 10.0