Active malware campaign has hijacked thousands of WordPress sites in just 15 days, has spiked to over 5K new infections daily
Active malware campaign uses thousands of WordPress sites to infect visitors — 15-day-old campaign has spiked in past 48 hours, with >5,000 new infections daily.
Context & Ripple Effects
This campaign extends a pattern the coverage has documented for years: in December 2014, the SoakSoak malware swept through 100,000+ self-hosted WordPress sites by exploiting a known flaw in the RevSlider plug-in, and by May 2015 an actively exploited WordPress bug had put millions of sites at risk. The new outbreak differs mainly in velocity — thousands of sites hijacked in 15 days and accelerating past 5,000 daily infections.
What makes the acceleration notable is that these are not zero-days but known-vulnerability compromises of the kind SoakSoak rode, suggesting the same unpatched-plugin long tail keeps being re-harvested. The later AccessPress backdoor disclosures would show the problem running deeper than patching hygiene, into the plug-in and theme supply chain itself.
First-order effects
- Owners of the thousands of hijacked sites face immediate cleanup and de-indexing risk while their pages serve malware to every visitor — turning each compromised site into an attack vector against its own audience.
Second-order effects
- WordPress plug-in and theme developers come under pressure to ship patches faster and prove their update channels are clean, since known-vulnerability exploitation at this scale makes laggard vendors the softest entry point.
- Security vendors and hosting providers gain a sales argument for managed updates and malware scanning aimed at self-hosted WordPress operators who have shown they will not patch on their own.
Third-order effects
- If each wave finds fresh unpatched sites years apart — SoakSoak in 2014, this campaign in 2015, the later supply-chain backdoors — the structural fix is consolidation toward hosted or auto-updating WordPress deployments, shrinking the self-managed long tail that attackers farm.
- Repeated compromise waves give regulators and enterprise buyers grounds to treat unmanaged CMS installs as a liability class, pushing WordPress security from site-owner responsibility toward platform-enforced defaults.
The trend: WordPress compromises keep recurring through the same unpatched plug-in and theme layer, steadily eroding the viability of self-managed installs and pushing the ecosystem toward platform-enforced updating.