Security News > 2016 > March > Popular WordPress plugin opens backdoor, steals user credentials (Help Net Security)

Popular WordPress plugin opens backdoor, steals user credentials (Help Net Security)
2016-03-07 20:07

If you are one of the 10,000+ users of the Custom Content Type Manager (CCTM) WordPress plugin, consider your site to be compromised and proceed to clean your installation up, Sucuri Security researchers have warned. After finding “a very suspicious auto-update.php file inside wp-content/plugins/custom-content-type-manager/ during the cleanup on an infected WP site, the researchers have begun digging, and discovered that: The file in question is a backdoor that can download additional files from a third-party … More →


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/r8ayM4XusxA/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 93 44 18 157
Plugin 2 0 13 1 0 14