安全攻防
evening
流行的 WordPress 插件脚本被篡改,在网站上植入隐藏后门
摘要
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites。
the
attacker
files
sites
and
2026-06-15
1 阅读
约1分钟阅读
info@thehackernews.com (The Hacker News)
字号:
攻击者篡改了运行 PushEngage、OptinMonster 和 TrustPulse 的 WordPress 网站所使用的可信 JavaScript 文件,将这些文件转变为闯入网站的一种方式。当站点管理员在加载文件时登录时,代码会在攻击者的控制下创建一个管理员帐户,并安装一个隐藏的插件,打开一条返回路径。普通访问者不会触发它
这篇文章对您有帮助吗?
订阅66必读
每日精选科技资讯,直达你的邮箱