WordPress Plugin Buyout Turns Into Dormant Backdoor Risk

A plugin acquisition can turn into a delayed compromise path. The dangerous part is not the sale itself. It is that a backdoor can sit quietly in widely trusted WordPress code and then activate later to push malicious code across sites that never expected the owner change to matter. The affected Essential Plugin portfolio was reportedly altered after the company was bought, then went dormant until it began distributing malicious code earlier this month. The plugins were used on more than 20,000 active WordPress installations, and Essential Plugin says it has over 400,000 installs and more than 15,000 customers. The forward risk is persistence. Even after the plugins are removed from the WordPress directory, any site that still has an affected plugin installed can remain exposed until the compromised code is found and removed.

Part of the PlainSec briefing for 2026-04-16

Sources