Malicious PHP snippets in WPCode

Malicious PHP snippets in WPCode

During the analysis and treatment of the infected site, malicious code was found embedded in the Code Snippets plugin. The main function of the malicious code was to redirect users once upon their first visit to the site, as well as to hide the plugin’s management form in the WordPress admin panel. This makes it difficult to detect the threat and increases the likelihood of a long-term presence of malicious code on a web resource.

This type of infection is quite common in the WordPress environment and causes a lot of inconvenience to website owners. Its main functionality is related to hiding malicious code and redirects on the website.

Plugin Security Certification (PSC-2025-64552): “Breadcrumb NavXT” – Version 7.4.1: Use Breadcrumb with Enhanced Security

Plugin Security Certification (PSC-2025-64552): “Breadcrumb NavXT” – Version 7.4.1: Use  Breadcrumb with Enhanced Security

Breadcrumb NavXT is a powerful WordPress plugin designed to generate breadcrumb trails for websites, providing users with a clear navigational structure. As the successor to Breadcrumb Navigation XT, it has been completely rebuilt to offer greater customization, performance, and compatibility with modern web standards. The plugin integrates seamlessly with WordPress themes, allowing both administrators and developers to configure breadcrumb settings effortlessly.

CVE-2024-13314 – Carousel, Slider, Gallery by WP Carousel – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13314 – Carousel, Slider, Gallery by WP Carousel – Stored XSS to JS Backdoor Creation – POC

The WP Carousel plugin is a popular WordPress plugin that allows users to create beautiful image, post, and WooCommerce product carousels effortlessly. With its user-friendly interface and extensive features, it has become a preferred choice for many WordPress site owners. However, a vulnerability (CVE-2024-13314) has been discovered in versions below 2.7.4, allowing attackers to exploit Stored Cross-Site Scripting (XSS), posing a significant security risk.

Plugin Security Certification (PSC-2024-64551): “ManageWP Worker” – Version 4.9.20: Use Management tool with Enhanced Security

Plugin Security Certification (PSC-2024-64551): “ManageWP Worker” – Version 4.9.20: Use Management tool with Enhanced Security

The ManageWP Worker plugin, with over 1 million downloads, is a powerful tool for managing multiple WordPress websites from a single dashboard. It offers features such as automated backups, security monitoring, bulk updates, and website cloning. However, from a security standpoint, plugins with administrative control over multiple sites require strict scrutiny to ensure data integrity and prevent potential exploitation.

CVE-2024-13208 – WP Google Map – Stored XSS to JS Backdoor Creation – POC

CVE-2024-13208 – WP Google Map – Stored XSS to JS Backdoor Creation – POC

Google Maps is an essential feature for many websites, enabling businesses and organizations to display interactive maps for better user engagement. WP Google Map is a WordPress plugin designed to simplify the integration of Google Maps into websites. This user-friendly tool provides extensive customization options, making it a favorite among WordPress users. However, recent security research uncovered a critical stored Cross-Site Scripting (XSS) vulnerability in the plugin, identified as CVE-2024-13208. This vulnerability has the potential to compromise the security of websites using the plugin, highlighting the importance of robust security measures.

Plugin Security Certification (PSC-2024-64549): “Antispam Bee” – Version 2.11.7: Use Antispam with Enhanced Security

Plugin Security Certification (PSC-2024-64549): “Antispam Bee” – Version 2.11.7: Use Antispam with Enhanced Security

AntiSpam Bee is a plugin that removes spam in comments on your blogs on WordPress sites. The plugin is popular and has 700 thousand users worldwide. AntiSpam Bee effectively removes spam comments and trackbacks. During the verification of the plugin for vulnerabilities and errors by the Cleantalk team, the plugin receives the PSC-2024-64549 certificate.

Plugin Security Certification (PSC-2024-64547): “Rank Math SEO” – Version 1.0.239: Use SEO with Enhanced Security

Plugin Security Certification (PSC-2024-64547): “Rank Math SEO” – Version 1.0.239: Use SEO with Enhanced Security

Rank Math SEO is a state-of-the-art plugin designed to simplify and enhance search engine optimization (SEO) for WordPress websites. Its use of artificial intelligence (AI) sets it apart, providing advanced tools to automate and optimize SEO tasks. However, alongside its powerful functionality, it is crucial to assess the plugin’s security practices to ensure safe deployment on websites.

Plugin Security Certification (PSC-2024-64546): “Polylang” – Version 3.6.6: Use Polyang with Enhanced Security

Plugin Security Certification (PSC-2024-64546): “Polylang” – Version 3.6.6: Use Polyang with Enhanced Security

The Polylang plugin is a powerful tool designed to create multilingual WordPress websites. With support for an unlimited number of languages, automatic integration with WordPress core features, and seamless performance, it has become a go-to solution for developers and site administrators alike. However, as with any plugin, security is paramount, and Polylang stands out for its commitment to safe coding practices.

Plugin Security Certification (PSC-2024-64550): “reCaptcha by BestWebSoft” – Version 1.80: Use reCaptcha with Enhanced Security

Plugin Security Certification (PSC-2024-64550): “reCaptcha by BestWebSoft” – Version 1.80: Use reCaptcha with Enhanced Security

The reCaptcha by BestWebSoft plugin is a robust security solution designed to protect WordPress forms from spam and bot-driven attacks. By integrating seamlessly with various forms, including login, registration, comments, and custom forms, the plugin ensures only legitimate users can access your website’s functionalities while blocking automated threats.