Supply Chain Attack on WordPress Marketing Plugins
Score: 9/10

Supply Chain Attack on WordPress Marketing Plugins

An attacker compromised the CDN API keys of OptinMonster, TrustPulse, and PushEngage to serve tampered JavaScript that creates rogue admin accounts on customer sites.

Executive Summary

In June 2026, a significant supply chain attack targeted users of OptinMonster, TrustPulse, and PushEngage WordPress plugins, potentially affecting over 1.2 million websites. The threat actor gained access to a CDN API key by exploiting a vulnerability in a third-party plugin (UpdraftPlus) on the vendor's marketing server. This allowed them to modify the JavaScript SDKs served from the CDN, injecting malicious code directly into the browser sessions of logged-in administrators.

The attack is technically significant because it bypasses traditional network-layer security by weaponizing the administrator's own session and valid nonces. Once executed in an admin's browser, the script silently creates a hidden administrator account and installs a self-hiding backdoor plugin. This grants the attacker full unauthenticated code execution and file system access while remaining invisible within the WordPress dashboard.

Sites that had these plugins active and an administrator logged in between June 12 and June 14, 2026, are at high risk. Immediate manual inspection of the server filesystem is required, as the malware actively hides its presence from the WordPress UI and standard plugin lists.

Key Details

Threat Name

OptinMonster Supply Chain Attack

Affects

—

Adversary

—

Malware/Tools

WPM File Manager & Shell, Content Delivery Helper, Database Optimizer, WowShipping Pro

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources