CybersecurityVerified Users Only
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
The Hacker NewsยทJune 15, 2026ยท1 min read
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
Read full article on The Hacker News โShare this article
Follow broker incidents, regulatory actions & market intelligence
Stay ahead with CLEAREX.MARKET
View all intelligence โ