Menu

Post image 1
Post image 2
1 / 2
0

Quick Page/Post Redirect Plugin: 5-Year Dormant Backdoor in 70K WordPress Sites

DEV Community·Satyam Rastogi·about 1 month ago
#UGwSEDkO
Reading 0:00
15s threshold

Originally published on satyamrastogi.com 70,000+ WordPress sites compromised via dormant backdoor in Quick Page/Post Redirect plugin. Five-year persistence, arbitrary code injection, unpatched vulnerability demonstrates plugin ecosystem supply chain risk. Quick Page/Post Redirect Plugin Backdoor: 70K Sites, 5-Year Dormant Persistence Executive Summary The Quick Page/Post Redirect plugin, deployed across 70,000+ WordPress installations, contained a dormant backdoor inserted approximately five years ago. The backdoor enables attackers to inject arbitrary PHP code directly into compromised sites, providing persistent access with minimal detection surface. This attack represents a textbook supply chain compromise targeting the WordPress plugin ecosystem-one of the internet's largest attack surfaces. From an attacker's perspective, this is a masterclass in patience-based supply chain infiltration.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More