CW Pakistan
  • Legacy
    • Legacy Editorial
    • Editor’s Note
  • Academy
  • Wired
  • Cellcos
  • PayTech
  • Business
  • Ignite
  • Digital Pakistan
  • PSEB
    • DFDI
    • Indus AI Week
  • PASHA
  • TechAdvisor
  • GamePro
  • Partnerships
  • PCWorld
  • Macworld
  • Infoworld
  • TechHive
  • TechAdvisor
0
0
0
0
0
Subscribe
CW Pakistan
CW Pakistan CW Pakistan
  • Legacy
    • Legacy Editorial
    • Editor’s Note
  • Academy
  • Wired
  • Cellcos
  • PayTech
  • Business
  • Ignite
  • Digital Pakistan
  • PSEB
    • DFDI
    • Indus AI Week
  • PASHA
  • TechAdvisor
  • GamePro
  • Partnerships
  • Wired

Over 20,000 WordPress Websites Infected After Backdoor Planted In Essential Plugin Following Acquisition

  • April 16, 2026
Total
0
Shares
0
0
0
Share
Tweet
Share
Share
Share
Share

More than 20,000 WordPress websites have been compromised following the discovery of a sophisticated supply chain attack in which a newly acquired plugin developer inserted hidden backdoors into more than 30 plugins, allowing malicious code to be silently distributed to any website running the affected software. The attack, which came to light after Austin Ginder, founder of web hosting firm Anchor Hosting, raised the alarm in a detailed blog post, has prompted WordPress to permanently remove all affected plugins from its official directory and issue security warnings to impacted site administrators.

The malicious company at the centre of the attack is called Essential Plugin, which claims its products have been installed more than 400,000 times and were being actively used by more than 15,000 customers, with the official WordPress repository showing more than 20,000 active installations at the time of the incident. According to Anchor Hosting’s investigation, version 2.6.7 of one of the affected plugins, Countdown Timer Ultimate, released on August 8, 2025, introduced the malicious code pathway while disguising the change behind a routine-looking compatibility note, with the attack then weaponised on April 5 and 6, 2026. The backdoor operated by phoning home to a server controlled by the attacker, pulling instructions, and using an unsafe deserialization flow to execute arbitrary code across infected installations, effectively giving the attacker remote control over every affected website without needing to breach each one individually.

The delayed activation is one of the most significant details of the entire incident. The malicious pathway was introduced in August 2025 but not activated until April 2026, a gap of several months that allowed the ownership transition to fade from immediate scrutiny and gave the attacker’s infrastructure time to blend into the normal update history of the plugins. Ginder warned that WordPress users are not notified of any plugin’s change in ownership, exposing users to potential takeover attacks by new owners, and noted that this is the second known hijacking of a WordPress plugin discovered in as many weeks. WordPress’s response on April 7, 2026 included sending security warnings directly to site owners’ admin dashboards, permanently closing all 26 plugins in the Essential Plugin family so they could no longer be installed from the official directory, and releasing a forced update on April 8 that added code to block the phone-home functionality connecting infected sites to the attacker’s server. However, security researchers noted that the forced update did not automatically clean already-infected configuration files on affected sites, meaning website owners must still manually audit their installations and remove any compromised plugins. Essential Plugin has not issued a public response to the incident.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Share
Tweet
Share
Share
Share
Related Topics
  • Austin Ginder Anchor Hosting
  • Essential Plugin Supply Chain Attack
  • Open Source Supply Chain Risk
  • Supply Chain Attack WordPress
  • WordPress Cybersecurity
  • WordPress Malicious Plugin
  • WordPress Plugin Backdoor
  • WordPress Plugin Takeover
  • WordPress Plugins Removed
  • WordPress Security 2026
Previous Article
  • Business

JazzWorld Recognized At GDEIB Awards 2026 For Purpose Driven Diversity Equity And Inclusion Strategy

  • April 16, 2026
Read More
Next Article
  • Digital Pakistan

ConnectHear Expands Sign Language AI Nationwide In Partnership With GSMA And Ufone

  • April 16, 2026
Read More
You May Also Like
Read More
  • Wired

Foodpanda Partners With Karachi Traffic Police For Rider Safety Workshop

  • Press Desk
  • April 16, 2026
Read More
  • Wired

TikTok Removes Over 22 Million Videos In Pakistan In Q4 2025

  • Press Desk
  • April 16, 2026
Read More
  • Wired

KP Government Plans Internship Program For BS Students With Monthly Stipend

  • Press Desk
  • April 14, 2026
Read More
  • Wired

Pakistan Auto Sales Drop 9% Month-On-Month In March 2026 As Electric Vehicle Sales Surge 61 Percent

  • Press Desk
  • April 13, 2026
Read More
  • Wired

Pakistani Food Delivery Platform FoodPapa Suffers Major Data Breach With Entire Database Leaked Online

  • Press Desk
  • April 13, 2026
Read More
  • Wired

NED University Launches Two-Month Online AI-Powered Project Management Course For Future Leaders

  • Press Desk
  • April 13, 2026
Read More
  • Wired

LUMS Faculty Research On AI-Assisted Medical Diagnosis Published In Nature Health Journal

  • Press Desk
  • April 11, 2026
Read More
  • Wired

NED University Journal Of Research Launches Hybrid Open Access Publishing Option For Authors

  • Press Desk
  • April 11, 2026
Trending Posts
  • NIC Karachi Launches Cohort 15, Welcomes 36 Startups Into Pakistan’s Leading Incubation Ecosystem
    • April 16, 2026
  • KP Government Database Allegedly Leaked On Dark Web, Exposing Internal Credentials And User Data
    • April 16, 2026
  • ConnectHear Expands Sign Language AI Nationwide In Partnership With GSMA And Ufone
    • April 16, 2026
  • JazzWorld Recognized At GDEIB Awards 2026 For Purpose Driven Diversity Equity And Inclusion Strategy
    • April 16, 2026
  • inDrive Pakistan Sees Strong Eid Growth As Intercity Mobility Rises 1.5x And Deliveries Increase 1.6x
    • April 16, 2026
about
CWPK Legacy
Launched in 1967 internationally, ComputerWorld is the oldest tech magazine/media property in the world. In Pakistan, ComputerWorld was launched in 1995. Initially providing news to IT executives only, once CIO Pakistan, its sister brand from the same family, was launched and took over the enterprise reporting domain in Pakistan, CWPK has emerged as a holistic technology media platform reporting everything tech in the country. It remains the oldest continuous IT publishing brand in the country and in 2025 is set to turn 30 years old, which will be its biggest benchmark and a legacy it hopes to continue for years to come. CWPK is part of the SPIN/IDG Wakhan media umbrella.
Read more
Explore Computerworld Sites Globally
  • computerworld.es
  • computerworld.com.pt
  • computerworld.com
  • cw.no
  • computerworldmexico.com.mx
  • computerwoche.de
  • computersweden.idg.se
  • computerworld.hu
Content from other IDG brands
  • PCWorld
  • Macworld
  • Infoworld
  • TechHive
  • TechAdvisor
CW Pakistan CW Pakistan
  • CWPK
  • CXO
  • DEMO
  • WALLET

CW Media & all its sub-brands are copyrighted to SPIN-IDG Wakhan Media Inc., the publishing arm of NCC-RP Group. This site is designed by Crunch Collective. ©️1995-2026. Read Privacy Policy.

Input your search keywords and press Enter.