Web_Logo
Remote Support
Security Alert: WordPress Supply Chain Attack Hits 1.2 Million Sites
Home » Security Alerts  »  Security Alert: WordPress Supply Chain Attack Hits 1.2 Million Sites

Security Alert: WordPress Supply Chain Attack Hits 1.2 Million Sites

A sophisticated supply chain attack hit over 1.2 million WordPress websites via tampered CDN files belonging to three popular marketing plugins — OptinMonster, TrustPulse, and PushEngage. While the malicious files have since been removed, sites that were active during the affected window between approximately June 12 and June 14 may still be compromised.

  • What it is: An attacker compromised Awesome Motive's CDN by exploiting a vulnerability in the UpdraftPlus backup plugin on their server, then injected malicious JavaScript into SDK files served to customer websites.
  • Who is affected: Any WordPress site running OptinMonster, TrustPulse, or PushEngage between June 12 and June 14, 2026. With a combined install base of over 1.2 million sites, this is a broad exposure.
  • What the risk is: The injected code ran silently inside the browser of any logged-in administrator who loaded an affected page. It used that admin session to create hidden administrator accounts and install a concealed backdoor plugin, with credentials exfiltrated to an attacker-controlled server.
  • What to do: If your site uses any of these three plugins, check your WordPress admin user list immediately for any accounts you do not recognise and review installed plugins for anything unfamiliar. Update OptinMonster, TrustPulse, and PushEngage to their latest versions. Also update UpdraftPlus if installed, as the vulnerability that enabled the breach originates there.

We recommend all WordPress site owners check their admin panel now, even if you believe the risk window has passed — backdoor accounts created during this period will persist until manually removed. Sources: Patchstack, Sansec.