Close Menu

    Subscribe to Updates

    Get the latest creative tech news from Droid Expose about AI, Apps and Devices.

    What's Hot

    Google Finance Just Got a Real Upgrade, and There’s Finally an App for It

    June 26, 2026

    Snapchat’s App Icon Has Changed to a Sunglasses Ghost. Here’s the Likely Reason

    June 18, 2026

    We Called the Apple-Gemini Deal Back in April. Google Just Showed Developers What It Actually Looks Like

    June 18, 2026
    Facebook X (Twitter) Instagram YouTube
    Facebook X (Twitter) Instagram YouTube
    Droid ExposeDroid Expose
    • AI

      We Called the Apple-Gemini Deal Back in April. Google Just Showed Developers What It Actually Looks Like

      June 18, 2026

      I Tested Gemini 3.5 Flash Against Gemini 3 Flash Across 5 Real Challenges- Here’s What Actually Surprised Me

      May 30, 2026

      Apple’s Best Use of AI Yet Has Nothing to Do With Chatbots

      May 22, 2026

      Gemini 3.5 Flash Explained: Everything You Need to Know About Google’s Most Capable Fast Model

      May 21, 2026

      Google I/O 2026: Gemini 3.5 Flash, Our SynthID Experiment and More AI Announcements

      May 21, 2026
    • Software

      Google Finance Just Got a Real Upgrade, and There’s Finally an App for It

      June 26, 2026

      Snapchat’s App Icon Has Changed to a Sunglasses Ghost. Here’s the Likely Reason

      June 18, 2026

      iOS 27 Everything You Need to Know: What Apple Confirmed, What We Got Wrong, and What It Means for Your iPhone

      June 12, 2026

      Samsung’s Galaxy S25 Is Already Getting One UI 9 Testing and It’s Earlier Than Anyone Expected

      June 8, 2026

      We’ve Been Testing Android 17 Betas Since February and Here’s What Beta 4.1 Fixed

      June 6, 2026
    • Features

      We Called the Apple-Gemini Deal Back in April. Google Just Showed Developers What It Actually Looks Like

      June 18, 2026

      I Got a Privacy Email From Google Last Night and It Was Actually Worth Reading

      June 10, 2026

      We’ve Been Testing Android 17 Betas Since February and Here’s What Beta 4.1 Fixed

      June 6, 2026

      Xiaomi Just Made One of the Most Annoying Android to iPhone Problems Easier to Deal With

      June 4, 2026

      Meta Now Wants You to Pay for Instagram, Facebook, and WhatsApp- Here’s Why That Actually Makes Sense

      May 27, 2026
    • Security

      WhatsApp Is Testing After Reading Disappearing Messages on iPhone

      May 18, 2026

      After 3 Years I Found SimpMusic as a Spotify Alternative — But Here Is the Reality

      May 17, 2026

      Android and iPhone Users Finally Get End-to-End Encrypted RCS Messaging

      May 12, 2026

      Meta Ends End-to-End Encryption for Instagram DMs

      May 9, 2026

      Meta’s New AI Scans Bone Structure to Spot Underage Users

      May 5, 2026
    • News

      Google Finance Just Got a Real Upgrade, and There’s Finally an App for It

      June 26, 2026

      Snapchat’s App Icon Has Changed to a Sunglasses Ghost. Here’s the Likely Reason

      June 18, 2026

      We Called the Apple-Gemini Deal Back in April. Google Just Showed Developers What It Actually Looks Like

      June 18, 2026

      Samsung Is Reportedly Launching Three Foldables in July and the One Nobody Expected Is the Most Interesting

      June 1, 2026

      Meta Is Building an AI Pendant, More Smart Glasses, and a Wearables for Work Plan

      May 31, 2026
    Droid ExposeDroid Expose
    Home - 31 WordPress Plugins Banned After Discovery of Secret Backdoor
    Security

    31 WordPress Plugins Banned After Discovery of Secret Backdoor

    Tawsif RezaBy Tawsif RezaApril 20, 2026Updated:May 19, 2026No Comments3 Mins Read
    Facebook Twitter Email WhatsApp Copy Link
    WordPress backdoor
    Share
    Facebook Twitter LinkedIn Email WhatsApp Copy Link

    Our editorial team is comprised of skilled technology experts and developers. To ensure that our research is easy to understand in simple and plain English, we may use AI-assisted tools for grammatical refinement and structural smoothness. However, every technical insight, test, and experience displayed has been fully completed and verified by our human team. All content remains the original property of Droid Expose. See more in our Privacy Policy.

    The WordPress.org security team took the unprecedented step last week of permanently banning every plugin associated with the Essential Plugin developer account. The move follows a detailed forensic report by Austin Ginder, founder of Anchor Hosting, who discovered that the plugins were being used to inject spam and malicious redirects into thousands of websites.

    The attack was not a traditional hack. Instead, it was a “supply-chain” strike that began when the original owners of the plugin portfolio sold their business on a public marketplace.

    Table of Contents

    • The 8-Month Sleep
    • A Highly Sophisticated Attack
    • Is Your Site at Risk?
    • Recommendations for Site Owners
    • The Trust Problem in WordPress

    The 8-Month Sleep

    According to Ginder’s investigation, the backdoor was planted as far back as August 2025, shortly after a new buyer—identified only by the alias “Kris”—acquired the portfolio for a six-figure sum. The attacker intentionally kept the malicious code dormant for eight months to evade detection by security scanners.

    The weaponization finally began on April 5, 2026. The dormant code “phoned home” to a remote server, which then pushed a massive block of malicious PHP into the victim sites’ wp-config.php files. This allowed the attacker to display fake pages and spam links specifically to Googlebot, effectively hijacking the site’s SEO while remaining invisible to the actual website owners.

    A Highly Sophisticated Attack

    What makes this breach particularly alarming to security professionals is the level of technical sophistication involved. The attacker used an Ethereum smart contract to manage their command-and-control servers. Because the server addresses are stored on the blockchain, traditional domain takedowns are ineffective—the attacker can simply update the smart contract to point to a new server at any time.

    Is Your Site at Risk?

    The affected plugins cover a wide range of functions, from “Countdown Timer Ultimate” to “Popup Anything on Click” and “WP Team Showcase.” While WordPress has forced an automatic update to neutralize the “phone-home” mechanism, experts warn that this is only a temporary fix.

    According to security audits, the forced update does not clean the infected wp-config.php files. If your site was running one of these plugins between April 5 and April 7, it may still be serving hidden spam to search engines.

    Recommendations for Site Owners

    If you have any plugins from the “Essential Plugin” or “WP Online Support” brand installed, security experts recommend taking the following steps immediately:

    1. Delete the Plugin: Since these are now permanently closed on WordPress.org, they will no longer receive security updates.
    2. Audit your wp-config.php: Check the end of the file for any unusual code, especially if the file size has suddenly increased by about 6KB.
    3. Run a Full Security Scan: Use tools like Wordfence or Sucuri to ensure no secondary backdoors were left behind.

    You may also like to read: Google Announces Search Ban for Websites Using Back Button Hijacking

    The Trust Problem in WordPress

    This incident has reignited a debate about security within the WordPress plugin repository. Currently, WordPress does not notify users when a plugin changes ownership, making it easy for malicious actors to purchase established tools and “inherit” the trust of thousands of unsuspecting users.

    Austin Ginder case study supply chain attack Wordpress news Wordpress plugin banned Wordpress security
    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Articles

    Google Finance Just Got a Real Upgrade, and There’s Finally an App for It

    June 26, 2026

    Snapchat’s App Icon Has Changed to a Sunglasses Ghost. Here’s the Likely Reason

    June 18, 2026

    We Called the Apple-Gemini Deal Back in April. Google Just Showed Developers What It Actually Looks Like

    June 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Droid Selections

    Google Announces Search Ban for Websites Using Back Button Hijacking

    April 19, 2026

    Apple’s iPhone Ultra: The Foldable 18 Pro Lineup Leaks in Full

    May 15, 2026

    Instagram’s Instants New App to Rival Snapchat

    April 28, 2026

    Android 17 adds Proactive AI, Quantum Security, and a War on Doomscrolling

    May 14, 2026
    Our Reviews

    I Got a Privacy Email From Google Last Night and It Was Actually Worth Reading

    By Tawsif Reza

    I Was Using Windows 10 on My Old Intel Celeron N2815 and the System Lag Forced Me to Find an Ultra-Lightweight OS

    By Tawsif Reza

    I Tested Gemini 3.5 Flash Against Gemini 3 Flash Across 5 Real Challenges- Here’s What Actually Surprised Me

    By Tawsif Reza
    Droid Expose
    Facebook X (Twitter) Instagram Pinterest YouTube Telegram
    • About Us
    • Contact Us
    • Terms Of Use
    • Editorial Policy
    • Privacy Policy
    © 2026 Droid Expose. Powered by Droid Expose.

    Type above and press Enter to search. Press Esc to cancel.