Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


In this Discussion

New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access

Tony40Tony40 Member

Cybersecurity researchers have uncovered a new stealthy backdoor concealed within the "mu-plugins" directory in WordPress sites to grant threat actors persistent access and allow them to perform arbitrary actions.

Must-use plugins (aka mu-plugins) are special plugins that are automatically activated on all WordPress sites in the installation. They are located in the "wp-content/mu-plugins" directory by default.

What makes them an attractive option for attackers is that mu-plugins do not show in the ...

https://thehackernews.com/2025/07/hackers-deploy-stealth-backdoor-in.html

Comments

  • Wow

  • xemapsxemaps Member

    Good to know !
    I would never trust wordpress or similar content manager.
    I wouldn't speak about plugins...

Sign In or Register to comment.