Friday 26 June 2026 09:37:54 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#WordPress plugins


When the Vendor Update Turns Hostile: ShapedPlugin and the WordPress Trust Trap

Published: 18 June 2026 19:17Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A reported compromise of a plugin vendor’s update channel shows how routine maintenance can become a malware delivery path when the distribution layer itself is tampered with.

When a Premium WordPress Plugin Becomes the Trojan Horse

Published: 18 June 2026 02:16Category: Malware & BotnetsGeo: Asia / BangladeshAuthor: NEXUSGUARDIAN

A reported backdoor in paid ShapedPlugin add-ons shows how a trusted update path can turn routine maintenance into a supply-chain risk.

When a Trusted Plugin Becomes the Weak Link

Published: 16 June 2026 12:51Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A reported issue around OptinMonster and related WordPress tools highlights how one tainted delivery path can create a broad trust problem for site owners.

One Tampered Script, Many Silent Victims: The WordPress Supply-Chain Trap

Published: 16 June 2026 12:38Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A trusted marketing embed became the weak link, showing how one upstream JavaScript change can put huge numbers of WordPress sites at risk without touching them one by one.

Thousands of WordPress Plugin Bugs Put the Extension Layer Back Under the Microscope

Published: 06 June 2026 04:07Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A quarterly vulnerability count for WordPress plugins points to a familiar security pattern: third-party code keeps widening the attack surface, with XSS and SQL Injection among the issues drawing attention.