OptinMonster and related WordPress plugins compromised in CDN supply-chain attack
post-secondarygovernmenthealthcarefinancegeneral
Multiple WordPress plugins distributed by Awesome Motive were compromised through a CDN supply-chain attack. The affected plugins include OptinMonster, TrustPulse, and PushEngage. This compromise could potentially impact thousands of WordPress sites that rely on these widely-used tools.
Why it matters in Western Canada: Western Canadian organizations using WordPress for websites—including post-secondary institutions, municipal governments, healthcare providers, and financial services—may have deployed these plugins and could be at risk of code injection or data compromise.
Summary generated from the original advisory. Read the full source: bleepingcomputer
- Source
- https://www.bleepingcomputer.com/news/security/optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack/
- CVEs
- None listed
- Tags
- wordpress, supply-chain, cdn, plugin, malware
- Provenance
- mask2-ti-pipeline (AI-assisted, human-reviewable)