Previous All Posts Next

WordPress Backdoor Found on 200,000 Websites

Posted: September 18, 2017 to Cybersecurity.

Tags: Malware, Data Breach, Cloud Security

WordPress is a hugely popular website platform. One of the things that makes it popular is the number of free plugins that can easily add advanced features and functionality to sites. One of those plugins was designed to act as a backdoor to the estimated 200,000 websites using it. The plugin in question is called Display Widgets. Between June and September, it was removed and replaced several times. Here's a timeline.
  • Display Widgets was a legitimate, popular plugin and was sold to a new developer on June 21.
  • The new owner released version 2.6.0 right away. It was reported pretty quickly that the plugin has started adding extra code and downloading data from users' servers.
  • WordPress removed the plugin from its repository on June 23.
  • Version 2.6.1 was released a week later and included a file called geolocation.php. The plugin was able to post content to websites that had it again, but now it also blocked logged-in users from seeing the new spam content, making it harder to discover or edit.
  • WordPress removed it from the repository again on July 1.
  • Five days later, version 2.6.2 was released. This version included a switch to turn it off and was on the WordPress plugin repository for most of the month, until July 24, when it was reported to have been spamming websites again.
  • Version 2.6.3 was released over a month later on September 2. This version still had bad code in it and even updated some issues in geolocation.php, which the Powers That Be at WordPress to determine the developer was purposely publishing a malicious plugin.
  • It was removed again on September 8.
  • Version 2.7 was released on September 12, by WordPress's plugin team, although it's not available in the repository. An announcement states that version 2.7 is the same as version 2.0.5 and that it's clean. It goes on to say "This plugin is done. It’s not supported, it’s not worked on, nothing. So if you have it, upgrade. Otherwise, find something else to use."

Related Resources

Learn more about how Petronella Technology Group can help:

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now