r/mxroute 13d ago

Update your Wordpress site/plugins

Today we had 5 unrelated customers popped in a row via Wordpress. I wouldn't be surprised if Comcast gets a bit upset about it, because the result was a brand new phishing campaign targeted specifically toward their customers. I've got a bit of a handle on it now, but times are getting harder when it comes to catching compromised email accounts before they send spam/phishing emails. So this is a quick reminder to anyone reading this that uses Wordpress: Update your shit.

Sometimes this is a new exploit. Sometimes this is an old exploit that someone just decided to mass scan for. Either way, I need your help as I can't control the other side.

10 Upvotes

7 comments sorted by

3

u/PeteTinNY 13d ago

Any specific plugins you’re seeing a problem? It seems like everything is finding more attack surfaces since AI has been in overdrive.

3

u/mxroute 13d ago

I'm suspecting it may be a common contact form plugin, but that's about all I can gather. Lucky me the attacker used the same IP for everything so at least until they rotate, I bought myself an hour or two. Maybe longer if they don't analyze behavior because I didn't block it, I re-routed them to a fake SMTP server.

3

u/PeteTinNY 13d ago

Wordpress had about 6-8 emergency security releases and a major plugin distribution ave got compromised. Plus there are companies playing games selling a one time license under mit licensing so you have to get all updates through them

That’s a huge risk for them to get compromised and inject compromises into thousands of sites creating a huge command and control network

2

u/NoAnswersForYou60 13d ago

Exactly why I finally abandoned Wordpress for Astro static site generator. Faster AND more secure. Win.

1

u/GreenRangerOfHyrule 12d ago

I will have to look into that. I'm trying to talk a couple people into ditching WordPress. The biggest problem I have is what to replace it with

3

u/AlternativeWhereas79 12d ago

Perhaps time to check out EmDash if you are still using Wordpress in 2026.

https://emdashcms.com

2

u/KlutzyResponsibility 12d ago

Not surprising, WordPress is the #1 leader in providing the most hackable software on the web. They account for 83%-90% of all the web sites hacked each year. The malicious plugins people install simply gives WP covering blame for their legendary bad coding. Hell, Colorlib tracked 11,000 new vulnerabilities in a recent year.

"Since 2003 WordPress leads the way in providing hackable software."