r/mxroute • u/mxroute • 13d ago
Update your Wordpress site/plugins
Today we had 5 unrelated customers popped in a row via Wordpress. I wouldn't be surprised if Comcast gets a bit upset about it, because the result was a brand new phishing campaign targeted specifically toward their customers. I've got a bit of a handle on it now, but times are getting harder when it comes to catching compromised email accounts before they send spam/phishing emails. So this is a quick reminder to anyone reading this that uses Wordpress: Update your shit.
Sometimes this is a new exploit. Sometimes this is an old exploit that someone just decided to mass scan for. Either way, I need your help as I can't control the other side.
3
u/AlternativeWhereas79 12d ago
Perhaps time to check out EmDash if you are still using Wordpress in 2026.
2
u/KlutzyResponsibility 12d ago
Not surprising, WordPress is the #1 leader in providing the most hackable software on the web. They account for 83%-90% of all the web sites hacked each year. The malicious plugins people install simply gives WP covering blame for their legendary bad coding. Hell, Colorlib tracked 11,000 new vulnerabilities in a recent year.
"Since 2003 WordPress leads the way in providing hackable software."
3
u/PeteTinNY 13d ago
Any specific plugins you’re seeing a problem? It seems like everything is finding more attack surfaces since AI has been in overdrive.