Here at Jetpack, we have noticed an increase in the number of sites affected with a fake plugin ingeniously called: WordPress Editor. And since it's been happening more frequently, we decided to write about it.

Before we go any further, if you have this plugin installed and activated on your WordPress site, you should immediately follow these steps:

  1. Remove the plugin.
  2. Change your current admin password and make sure to use a strong one.
  3. Review all admin users; if the attacker had access to your site they may have created new users.
  4. Change passwords for any other valid admin accounts.
  5. Enable 2FA for all admin accounts.

Now, with that out of the way, let's see what this bad code does.

Continue reading "How Hackers Abuse Leaked Passwords for Profit"