Two rival hackers fought over a WordPress site, exposing a plugin zero-day
A WordPress website was compromised by two separate attacker groups who clashed over control of the infected server, leaving the site broken as collateral damage. One group used an authentication bypass vulnerability in the WPMU DEV Dashboard plugin, tracked as CVE-2026-15459, to install a malicious plugin and gain access; the flaw only existed when the plugin's API key was left blank. The first group planted cloaking malware to serve spam links to search crawlers while showing normal pages to human visitors. A second group later locked out the first by overwriting .htaccess rules, prompting the original attackers to retaliate by renaming the wp-content directory, effectively crashing the site. The incident went undetected by antivirus software, which scanned 373 files and flagged nothing, and was only unravelled through careful analysis of server access logs and database records.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in