Observed Signal · Apr 15, 2026 · Security Incident · Source: t3n · Impact: 2/5 · Sentiment: Negative
WordPress Plugins Infected with Backdoor
A security researcher, Austin Ginder, discovered that more than 30 WordPress plugins were modified to include a backdoor allowing attackers to inject malicious content into websites. The affected plugins — originally developed by an Indian team called WP Online Support and later sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed the collection Essential Plugin — remained dormant until the backdoor was activated in early April 2026. Injected payloads reportedly loaded spam links, redirects, fake pages and crypto-related links from a remote server, and the injections were cloaked so only Google’s crawler could see them. Essential Plugin says the infected addons had over 400,000 installs; the extensions have since been disabled in the WordPress store. Ginder published a patch and a removal recommendation for site operators.
The incident affects a large install base of WordPress plugins (>400k installs), enabling cloaked malicious content and potential SEO, brand-safety and fraud impacts for many publisher sites; however it is a targeted plugin supply-chain compromise rather than an industry-wide platform policy or major platform technical change.
Track WordPress Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Web developer Austin Ginder discovered and documented the issue.
- More than 30 WordPress plugins were modified to include a backdoor.
- The plugin collection was originally developed by WP Online Support and sold in early 2025 to an anonymous buyer nicknamed "Kris," later renamed Essential Plugin.
- The backdoor was activated in early April 2026 and reportedly served spam links, redirects, fake pages and crypto-links; injected content was cloaked to be visible only to Google’s crawler.
- Essential Plugin reported the affected plugins had been installed more than 400,000 times; the plugins have been disabled and removed from the WordPress store.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Backdoor in WordPress Plugins Hits 400,000 Installations
A backdoor hidden in more than 30 WordPress plugins has been discovered by web developer Austin Ginder. The plugin collection was originally developed by WP Online Support and reportedly sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed it Essential Plugin. The malicious code—activated in early April 2026—injected spam links, redirects, fake pages and crypto links that pointed to public blockchain endpoints; changes were crafted so only Google’s crawler could see them. Essential Plugin reports the affected extensions had over 400,000 installations. WordPress has removed and disabled the extensions from the plugin directory. Users who installed any of the listed plugins are advised to remove them or apply a patch published by Ginder and to audit sites for unauthorized changes.
Backdoors Found in Dozens of WordPress Plugins
Security researchers discovered a backdoor inserted into dozens of WordPress plug-ins after the plug-in maker Essential Plugin was acquired by a new corporate owner. Anchor Hosting founder Austin Ginder alerted the community after finding the supply‑chain compromise; the malicious code reportedly sat dormant for months and activated earlier in April 2026 to distribute additional malicious payloads to sites running the affected plug-ins. Essential Plugin states it has over 400,000 installs and more than 15,000 customers, while WordPress shows the affected plug-ins in over 20,000 active installations. The plug-ins have been removed from the WordPress directory and marked permanently closed. Site owners are advised to check for and remove any affected plug-ins.
BdThemes Supply-Chain XSS Leads to Web Shells
Wordfence Threat Intelligence reported a critical supply-chain compromise in the BdThemes ecosystem where attackers wrote malicious JSON to the vendor's static storage. A DOM XSS (unescaped display_id in the Biggopti JSON) executed inside logged-in WordPress administrator browsers, causing external scripts (w2.js / x.js) to run. The payloads used administrator sessions to create rogue admin accounts, upload a fake plugin, deploy a web shell (emer-run.php), install MU-plugin persistence, and hide created accounts while beaconing results to a C2. Active attacks were observed on August 7, 2026 and the vendor JSON returned to clean on August 8. Affected plugins include Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, Smart Admin Assistant.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
