
WordPress Plugin Backdoors Hit 400,000 Sites in 2026
Someone bought a WordPress plugin company, planted backdoors across 26 to 30 plugins, waited eight months, and then activated them to hit over 400,000 websites at once. The attack used an Ethereum smart contract








