CVE-2026-10795
CVSS 8.1 HIGH: the UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all… EPSS 0.3% (25th percentile).
Vulnerabilities · 91 days ago
A vendor script is only as trusted as the account behind it. Here, the break was not just poisoned plugin JavaScript. Awesome Motive says attackers first reached a marketing server through an unrelated UpdraftPlus flaw, stole CDN credentials, and used them to push malicious code that could create rogue admins and hide a backdoor plugin on any site that loaded it.
PushEngage has confirmed the exposure and published notice. Sansec tied the malicious JavaScript to OptinMonster, TrustPulse, and PushEngage, with OptinMonster and TrustPulse seeing a brief window on June 12 and PushEngage exposed longer into June 14. The three plugins reach more than 1.2 million sites, and the hidden plugin has shown up as Content Delivery Helper v2.7.1 and Database Optimizer v2.9.4.
The usual dashboard check can miss the real persistence layer, because the script only wakes up when a logged-in WordPress admin loads the page and then uses that session to plant a durable foothold. Removing the bad CDN file does not prove the site is clean if the attacker already created a new admin or left a self-hiding plugin behind.
CVSS 8.1 HIGH: the UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all… EPSS 0.3% (25th percentile).
3 sources covering this story
Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Tampered JavaScript in three Awesome Motive plugins exposed WordPress sites to rogue admin accounts and hidden backdoors.
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
Part of the PlainSec briefing for 2026-06-16