$ intel.mask2.ca

ADVISORY · 2026-06-15 · SRC BLEEPINGCOMPUTER · HIGH
2026-06-15 high REL 6/10

OptinMonster and related WordPress plugins compromised in CDN supply-chain attack

post-secondarygovernmenthealthcarefinancegeneral

Multiple WordPress plugins distributed by Awesome Motive were compromised through a CDN supply-chain attack. The affected plugins include OptinMonster, TrustPulse, and PushEngage. This compromise could potentially impact thousands of WordPress sites that rely on these widely-used tools.

Why it matters in Western Canada: Western Canadian organizations using WordPress for websites—including post-secondary institutions, municipal governments, healthcare providers, and financial services—may have deployed these plugins and could be at risk of code injection or data compromise.


Summary generated from the original advisory. Read the full source: bleepingcomputer

Source
https://www.bleepingcomputer.com/news/security/optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack/
CVEs
None listed
Tags
wordpress, supply-chain, cdn, plugin, malware
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)