Threats & Adversaries · Credential Theft

Attackers Weaponize 250+ WordPress Sites to Steal Credentials

Threat actors compromised more than 250 WordPress sites to inject fake Cloudflare 'ClickFix' CAPTCHA prompts that trick visitors into running a multi-stage Windows infostealer.

3 sources · Mar 16

Timeline

Sources

Part of the PlainSec briefing for 2026-03-16

Every edition of this story: Attackers Weaponize 250+ WordPress Sites to Steal Credentials

More from today