Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
vendor-distribution-compromisepersistence-methodinternet-facing-service-vulnerabilitycommand-and-control-method

Backdoored Essential Plugin WordPress Add-ons Compromised Thousands of Sites

Updated 2mo agoFirst seen Apr 14, 20266 sources

A supply-chain attack hit the Essential Plugin WordPress portfolio after the plugin business was reportedly acquired by a new owner who inserted a hidden backdoor into trusted add-ons used by thousands of websites. Researchers said the malicious code was added to Countdown Timer Ultimate version 2.6.7 in August 2025 as a PHP deserialization backdoor, then left dormant for about eight months before activating in early April 2026. Once triggered, affected sites contacted analytics.essentialplugin.com, received additional payloads, and had malicious code written into wp-config.php.

The compromise allowed attackers to serve hidden spam links, fake pages, and redirects to Googlebot while remaining largely invisible to site owners. WordPress.org subsequently closed all 31 Essential Plugin entries in the plugin directory and pushed version 2.6.9.1 to remove the phone-home behavior, but reports warned that the update did not clean already-compromised wp-config.php files. Hosting providers and researchers urged administrators to manually inspect and remove any still-installed malicious plugins and persistence left on their servers, underscoring the risk that plugin ownership changes can turn established WordPress software into a malware distribution channel.

Share:
Backdoored Essential Plugin WordPress Add-ons Compromised Thousands of Sites
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 14, 20262mo ago

Researchers publicly disclose the WordPress plugin supply-chain attack

By mid-April 2026, reporting and researcher analysis revealed that dozens of Essential Plugin-associated WordPress plugins used on thousands of websites had been backdoored after an ownership change. The disclosure highlighted the broader risk that WordPress users are not automatically notified when plugin ownership changes hands.

Apr 7, 20263mo ago

WordPress.org pushes cleanup update for affected plugins

WordPress.org released version 2.6.9.1 to remove the plugins' phone-home mechanism, but the update did not remediate malicious changes already written into compromised wp-config.php files. Site owners were warned to manually inspect and clean infected installations.

WordPress.org closes compromised Essential Plugin plugins

On April 7, 2026, WordPress.org shut down all 31 Essential Plugin plugins in the directory and marked them closed following discovery of the compromise. The plugins were removed from distribution to limit further exposure.

Apr 5, 20263mo ago

Dormant backdoor activates and pushes malicious payloads

On April 5–6, 2026, the hidden backdoor began contacting analytics.essentialplugin.com and delivering malicious code to affected WordPress sites. The malware modified wp-config.php to serve hidden spam links, fake pages, and redirects to Googlebot while staying largely invisible to site owners.

Aug 8, 202511mo ago

Backdoor inserted into Essential Plugin codebase

The new owner allegedly inserted a PHP deserialization backdoor into Countdown Timer Ultimate version 2.6.7, with the malicious code then remaining dormant for months across the Essential Plugin portfolio.

Attacker acquires Essential Plugin business

A threat actor reportedly purchased the Essential Plugin WordPress plugin business from founder Minesh Shah via Flippa, setting up a supply-chain compromise through a trusted plugin portfolio.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
1 linked
Wordpress
Organizations
6 linked
Anchor HostingFlippaWordpressEssential PluginAnchorTechCrunch
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Backdoored Essential Plugin WordPress Add-ons Compromised Thousands of Sites | Mallory