menu
techminis

A naukri.com initiative

google-web-stories
source image

Cybersafe

2w

read

39

img
dot

Image Credit: Cybersafe

WordPress MU-Plugins exploited by hackers for stealthy attacks

  • Hackers are exploiting the WordPress Must-Use Plugins (MU-Plugins) directory to inject and execute malicious code on websites undetected.
  • MU-Plugins are a special category of WordPress plugins that run automatically on every page load, making them an attractive target for cybercriminals.
  • Researchers have identified three primary malware payloads being deployed in the MU-Plugins directory: redirect.php, index.php, and custom-js-loader.php.
  • To mitigate these threats, WordPress administrators are advised to regularly update plugins and themes, remove unused ones, and conduct routine security audits.

Read Full Article

like

2 Likes

For uninterrupted reading, download the app