Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

arstechnica.com
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Malicious updates available from WordPress.org create attacker-controlled admin account.