#7
BleepingComputer
general
April 29, 2026 at 22:13 UTC
Popular WordPress redirect plugin hid dormant backdoor for years
By Bill Toulas
AI Summary
The Quick Page/Post Redirect WordPress plugin, installed on over 70,000 sites, contained a dormant backdoor added five years ago that enables arbitrary code injection. The long-term compromise demonstrates sophisticated supply chain persistence tactics targeting popular WordPress infrastructure.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →