7 WAY SECURITY

7 WAY SECURITY

(+57) 3007265036
Email: [email protected]

7WAY SECURITY
Bogotá, Cra 49 # 128B - 31 - My desk - Of. 201

GET IN TOUCH WITH ONE OF OUR EXPERTS: 3007265036
  • HOME
  • ABOUT US
  • SECTORS
    • FINANCIAL
    • ENERGY
    • TELECOMMUNICATIONS
    • HEALTH
    • TRANSPORT
  • SERVICES
    • OFFENSIVE
      • Ethical Hacking
      • Red Team Testing plans
      • 7Way Ops
      • Pentesting on Demand
      • Anguilla
      • Certified Testing
    • DEFENSIVE
      • Training
    • INTELLIGENCE
      • Cattleya
      • Threat Hunting
    • INCIDENT RESPONSE
      • Incident Response
      • Digital Investigations
      • CSIRT 711
    • CONSULTANCY
      • Black Team
  • JOIN THE TEAM
    • Supply Network Team
    • Offer Blue Team
    • Offer Black Team
    • Offer Orange Team
    • Offer Green Team
    • Offer Practitioners
    • Offer Gray Team
    • Offer White Team
  • PRICES
  • CONTACT
  • BLOG
  • Home
  • Cybersecurity
  • Blue Teams
  • Critical Alert in WordPress: Hackers Exploiting Vulnerabilities in mu-Plugins
June 3, 2026

Critical Alert in WordPress: Hackers Exploiting Vulnerabilities in mu-Plugins

11
Blue Team
Blue Teams
Monday, 28 April 2025 / Published in Blue Teams, Cybersecurity, Threat Intelligence, Security monitoring, Incident Response, Defensive Security

Critical Alert in WordPress: Hackers Exploiting Vulnerabilities in mu-Plugins

Alerta_critica_Wordpress_exploit_7way_security

Do you have a WordPress website? According to findings from security company Sucuri, since the second half of February 2025, there has been a surge in attacks targeting WordPress sites by exploiting vulnerabilities in a specific class of default plugins, commonly known as mu-plugins.

What are the mu-plugins?

Mu-plugins (must-use plugins) refer to a special category of WordPress plugins that are loaded automatically without being manually activated via the standard plugins dashboard (admin interface). Essentially, these are PHP files stored in the wp-content/mu-plugins/ directory and are often overlooked during routine security audits.

Due to the fact that mu-plugins are executed on every page load, attackers exploit this behavior to carry out malicious activities such as credential theft, malicious code injection, and modification of HTML output parameters.

wp-content/mu-plugins/

Source: wp-kana.com

Indicators of Compromise (IoCs)

Signs of infection may include:

  1. A spike in unauthorized redirects to external websites
  2. Presence of files with ambiguous or unusual names in the wp-content/mu-plugins/ directory
  3. Unexplained, sustained spikes in server resource consumption

Analyzing the mu-Plugin Vulnerability:

Analysis of infected samples has identified three primary .php files within the wp-content/mu-plugins/ directory that exhibit confirmed malicious activity:

  • redirect.php is altered to display fake website update notifications that redirect end-users to malicious external sites.
  • index.php contains traces of webshells that execute arbitrary obfuscated code, granting extensive control over the compromised WordPress site.
  • custom-js-loader.php includes spam injection scripts aimed at manipulating search engine rankings to benefit malicious websites.

These techniques show clear patterns consistent with the LummaStealer malware, a sophisticated "stealer" threat primarily targeting Windows systems.

Repositorio GitHub de yon3zu

Source: GitHub Repository of yon3zu

Each of the three compromised files contains specific characteristics that warrant individual analysis.

1. Fake Updates via redirect.php:

The malware mimics WordPress's legitimate redirect function, displaying a fake update panel to trick users into viewing or downloading malicious plugins. Advanced versions of the script include mechanisms to bypass search engine crawlers and suppress warnings from concurrent redirects.

CAPTCHA falso asociado a un redirect.php

Example: Fake CAPTCHA from an infected redirect.php file

2. Webshell via index.php:

This scenario is more complex, as it allows attackers to execute a wide range of malicious behaviors through remote access to the compromised website.

script remoto .php
script remoto .php #2

Example: Remote .php script hosted on GitHub, related to the 403WebShell toolkit

3. Spam Injection via custom-js-loader.php:

This technique uses JavaScript injection to identify images and GIFs on the affected site and replace them with links typically associated with pornography, severely damaging the site’s reputation.

More sophisticated variants intercept clickable areas of the website, triggering unwanted pop-ups when users click on links.

inyección JavaScript

Source: Sucuri

STRENGTHEN YOUR WEBSITE WITH THE WORDPRESS HARDENING KIT AND ACT NOW.
Don't be the next victim! Prevent your website from being attacked! With this 👉Free Hardening Toolkit for WordPress you will have a set of essential tools so that you can strengthen the security of your CMS in a clear and simple way.

Identifying Vulnerability Entry Points in WordPress Sites

The main attack vectors include:

  • Exploitation of Unpatched Vulnerabilities

    • CVE-2024-27956 (CVSS score: 9.9) – Unauthenticated SQL injection in the WordPress Automatic Plugin – AI Content Generator and Auto Poster.

    • CVE - 2024-25600 (score CVSS: 10,0) – Unauthenticated remote code execution in the Bricks theme.

    • CVE-2024-8353 (score CVSS: 10.0) – Unauthenticated PHP object injection and RCE in the GiveWP plugin.

    • CVE-2024-4345 (score CVSS: 10.0) – Unauthenticated arbitrary file upload in Startklar Elementor Addons for WordPress.

  • Compromised WordPress Admin Credentials
  • Lack of Regular Security Audits in Provisioning Environments

Recommendations

  1. Perform a full WordPress scan, focusing on abnormal files in the wp-content/mu-plugins/ directory
  2. Review the status of admin accounts, remove those no longer in use or not linked to confirmed personnel
  3. Ensure WordPress core, themes, and plugins are fully updated
  4. Rotate admin passwords regularly
  5. Enable two-factor authentication 2FA
  6. Set up File Integrity Monitoring (FIM) using plugins that alert on unexpected changes

Key Takeaway

The foundation for mitigating these threats lies in strengthening security through continuous monitoring and regular updates to prevent attackers from exploiting increasingly sophisticated vulnerabilities.

References:

  • https://thehackernews.com/2025/03/hackers-exploit-wordpress-mu-plugins-to.html
  • https://patchstack.com/articles/new-year-new-threats-q1-2025s-most-exploited-wordpress-vulnerabilities/
  • https://www.bleepingcomputer.com/news/security/hackers-abuse-wordpress-mu-plugins-to-hide-malicious-code/
  • https://blog.sucuri.net/2025/03/hidden-malware-strikes-again-mu-plugins-under-attack.html
  • https://blog.sucuri.net/2025/02/hidden-backdoors-uncovered-in-wordpress-malware-investigation.html
  • https://github.com/yon3zu/403WebShell

Does your company depend on WordPress or other digital assets exposed to the internet?
Not just update plugins.
It is time to monitor how you use your brand name on the network and act before the damage is irreversible.
👉 Click here to see how we can help

Blue Team

William Ardila

Blue Teams

Share the knowledge:
Tagged under: Critical Alert, BLUE TEAM, exploitation, Hackers, mu-plugins, defensive security, vulnerability analysis, WordPress

What you can read next

Exposición_de_datos comercializados_en mercados_negros_7WS
Data Exposure on Black Markets
Suplantaciones_en_Colombia_Cattleya_7way_Security_2025
Phishing trademark colombian
Ciberseguridad_en_Colombia_5_claves_para_identificar_activos
Cybersecurity in Colombia: 5 Keys to Identifying Assets

SEARCH

RECENT ARTICLES

  • Proveedor_ciberseguridad_Colombia_7way_security

    Avoid Risks: How to choose your Cybersecurity Provider in Colombia?

    En el sector financiero, donde la información s...
  • protección_de_datos_personales_en_Colombia_y_ciberseguridad_empresarial_7way_security

    Data Protection: Risk Management and Compliance in Colombia

    Every January, is commemorated in Colombia the Day of l...
  • Ciberseguridad_2026_ SOC_e_inteligencia_de_amenazas_7WS

    Cybersecurity 2026: SOC and Threat Intelligence

    The start of 2026 reinforces a reality as cone...
  • migración de infraestructura TI — 5 pasos para modernizarla

    Is Your Infrastructure Already Migrated? 5 Steps to Modernize It

    When the speed of evolution of the threat...
  • Week of Cybersecurity 2025: digital Culture safe

    During the most recent Week of the Cibersegur...

FILES

  • February 2026
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • April 2021

CATEGORIES

  • Blue Teams
  • Cybersecurity
  • Development
  • Secure development
  • Documentation
  • Hardering
  • Threat Intelligence
  • Security monitoring
  • MVP
  • Networking
  • Orange Team
  • Pentesting
  • Penetration testing advanced
  • Network Team
  • Incident Response
  • Defensive Security
  • Startup
  • Technology
  • Threat Intelligence

TOPICS OF INTEREST

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

ASK FOR ADVICE FROM OUR EXPERTS

Please, fill out this form and we will contact you as soon as possible

7way_security_ciberseguridad_de_la_manera_correcta_4

7WAY SECURITY

CIBERSECURITY THE RIGHT WAY.

POLICY FOR THE MANAGEMENT OF PERSONAL DATA

CONTACT us

Bogotá: Cra 49 # 128b 31 Office 201 – (601) 805 24 02

Whatsapp: (+57) 300 726 5036

E-mail: [email protected]

Business Developer: [email protected]

Resumes / CVs [email protected]

 

 

  • GET SOCIAL

© 2022 All rights reserved. 7WAY SECURITY.

TOP
EN
ES