CW Pakistan
  • Legacy
    • Legacy Editorial
    • Editor’s Note
  • Academy
  • Wired
  • Cellcos
  • PayTech
  • Business
  • Ignite
  • Digital Pakistan
  • PSEB
    • DFDI
    • Indus AI Week
  • PASHA
  • TechAdvisor
  • GamePro
  • Partnerships
  • PCWorld
  • Macworld
  • Infoworld
  • TechAdvisor
0
0
0
0
0
Subscribe
CW Pakistan
CW Pakistan CW Pakistan
  • Legacy
    • Legacy Editorial
    • Editor’s Note
  • Academy
  • Wired
  • Cellcos
  • PayTech
  • Business
  • Ignite
  • Digital Pakistan
  • PSEB
    • DFDI
    • Indus AI Week
  • PASHA
  • TechAdvisor
  • GamePro
  • Partnerships
  • Wired

Over 20,000 WordPress Websites Infected After Backdoor Planted In Essential Plugin Following Acquisition

  • April 16, 2026
Total
0
Shares
0
0
0
Share
Tweet
Share
Share
Share
Share

More than 20,000 WordPress websites have been compromised following the discovery of a sophisticated supply chain attack in which a newly acquired plugin developer inserted hidden backdoors into more than 30 plugins, allowing malicious code to be silently distributed to any website running the affected software. The attack, which came to light after Austin Ginder, founder of web hosting firm Anchor Hosting, raised the alarm in a detailed blog post, has prompted WordPress to permanently remove all affected plugins from its official directory and issue security warnings to impacted site administrators.

The malicious company at the centre of the attack is called Essential Plugin, which claims its products have been installed more than 400,000 times and were being actively used by more than 15,000 customers, with the official WordPress repository showing more than 20,000 active installations at the time of the incident. According to Anchor Hosting’s investigation, version 2.6.7 of one of the affected plugins, Countdown Timer Ultimate, released on August 8, 2025, introduced the malicious code pathway while disguising the change behind a routine-looking compatibility note, with the attack then weaponised on April 5 and 6, 2026. The backdoor operated by phoning home to a server controlled by the attacker, pulling instructions, and using an unsafe deserialization flow to execute arbitrary code across infected installations, effectively giving the attacker remote control over every affected website without needing to breach each one individually.

The delayed activation is one of the most significant details of the entire incident. The malicious pathway was introduced in August 2025 but not activated until April 2026, a gap of several months that allowed the ownership transition to fade from immediate scrutiny and gave the attacker’s infrastructure time to blend into the normal update history of the plugins. Ginder warned that WordPress users are not notified of any plugin’s change in ownership, exposing users to potential takeover attacks by new owners, and noted that this is the second known hijacking of a WordPress plugin discovered in as many weeks. WordPress’s response on April 7, 2026 included sending security warnings directly to site owners’ admin dashboards, permanently closing all 26 plugins in the Essential Plugin family so they could no longer be installed from the official directory, and releasing a forced update on April 8 that added code to block the phone-home functionality connecting infected sites to the attacker’s server. However, security researchers noted that the forced update did not automatically clean already-infected configuration files on affected sites, meaning website owners must still manually audit their installations and remove any compromised plugins. Essential Plugin has not issued a public response to the incident.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Share
Tweet
Share
Share
Share
Related Topics
  • Austin Ginder Anchor Hosting
  • Essential Plugin Supply Chain Attack
  • Open Source Supply Chain Risk
  • Supply Chain Attack WordPress
  • WordPress Cybersecurity
  • WordPress Malicious Plugin
  • WordPress Plugin Backdoor
  • WordPress Plugin Takeover
  • WordPress Plugins Removed
  • WordPress Security 2026
Previous Article
  • Business

JazzWorld Recognized At GDEIB Awards 2026 For Purpose Driven Diversity Equity And Inclusion Strategy

  • April 16, 2026
Read More
Next Article
  • Digital Pakistan

ConnectHear Expands Sign Language AI Nationwide In Partnership With GSMA And Ufone

  • April 16, 2026
Read More
You May Also Like
Read More
  • Wired

Marka-e-Haq Lego Tribute: One Year On In AI

  • Press Desk
  • May 6, 2026
Read More
  • Wired

MyCloud By Multinet Launches Pakistan’s First GPU-As-A-Service Platform For AI And Machine Learning Workloads

  • Press Desk
  • May 6, 2026
Read More
  • Wired

Punjab Government Formally Exempts IT Companies, Call Centers And Gyms From Market Closure Timings

  • Press Desk
  • May 6, 2026
Read More
  • Wired

Pakistan Faces Electric Bike And Scooter Shortage As Surging Petrol Prices Drive Demand Beyond Supply

  • Press Desk
  • May 5, 2026
Read More
  • Wired

Careem Conducts Fresh Round Of Layoffs With Pakistani Developers Among Those Affected

  • Press Desk
  • May 5, 2026
Read More
  • Wired

Pakistan Could Benefit From ADB’s $70 Billion AI-Powered Energy And Digital Infrastructure Plan

  • Press Desk
  • May 5, 2026
Read More
  • Wired

Pakistani Researchers Present At Nanjing International Forum On Artificial Intelligence And Green Sustainability

  • Press Desk
  • May 5, 2026
Read More
  • Wired

UK Launches Noor, Pakistan’s First Voice-Based AI Platform For Disaster Response

  • Press Desk
  • May 5, 2026
Trending Posts
  • NED University Software Engineering Department To Showcase AI And Tech Final Year Projects At FYDP Expo 2026
    • May 6, 2026
  • Pakistan Launches RFP For National Open Data Ecosystem To Strengthen Digital Infrastructure
    • May 6, 2026
  • KhiNext Launches AI Expo 26 In Karachi To Showcase Artificial Intelligence Solutions And Innovation
    • May 6, 2026
  • Telenor Pakistan Secures Multiple Wins At Effie Pakistan 2026 Across Health, Youth And Telecom Categories
    • May 6, 2026
  • AI Seekho Phase II Launches Google Antigravity Hackathon With PKR 2.5 Million Prize Pool For AI Agent Developers
    • May 6, 2026
about
CWPK Legacy
Launched in 1967 internationally, ComputerWorld is the oldest tech magazine/media property in the world. In Pakistan, ComputerWorld was launched in 1995. Initially providing news to IT executives only, once CIO Pakistan, its sister brand from the same family, was launched and took over the enterprise reporting domain in Pakistan, CWPK has emerged as a holistic technology media platform reporting everything tech in the country. It remains the oldest continuous IT publishing brand in the country and in 2025 is set to turn 30 years old, which will be its biggest benchmark and a legacy it hopes to continue for years to come. CWPK is part of the SPIN/IDG Wakhan media umbrella.
Read more
Explore Computerworld Sites Globally
  • computerworld.es
  • computerworld.com.pt
  • computerworld.com
  • cw.no
  • computerworldmexico.com.mx
  • computerwoche.de
  • computersweden.idg.se
  • computerworld.hu
Content from other IDG brands
  • PCWorld
  • Macworld
  • Infoworld
  • TechAdvisor
CW Pakistan CW Pakistan
  • CWPK
  • CXO
  • DEMO
  • WALLET

CW Media & all its sub-brands are copyrighted to SPIN-IDG Wakhan Media Inc., the publishing arm of NCC-RP Group. This site is designed by Crunch Collective. ©️1995-2026. Read Privacy Policy.

Input your search keywords and press Enter.