Active malware campaign has hijacked thousands of WordPress sites in just 15 days, has spiked to over 5K new infections daily
Dan Goodin / Ars Technica :
Context & Ripple Effects
The 15-day infection wave is the latest chapter in a pattern Ars has tracked since at least December 2014, when the [[a:824546|SoakSoak malware infected more than 100,000 self-hosted WordPress sites through a known RevSlider plug-in flaw]]. Five months before this campaign, researchers flagged an actively exploited WordPress bug putting millions of sites at risk.
What makes the current spike notable is velocity rather than novelty: over 5,000 new infections a day against a platform whose long tail of self-hosted installs and third-party plug-ins repeatedly fails to patch known vulnerabilities — the same gap later exploited by backdoor admin accounts ([[a:939802]]) and the AccessPress theme-and-plug-in backdoors.
First-order effects
- Thousands of site owners face cleanup on compressed timelines — removing injected code, resetting credentials, and restoring from backups — while their visitors are served malicious content in the interim.
- Hosting providers absorbing the traffic and abuse reports must quarantine infected accounts or risk their own IPs and shared infrastructure being flagged.
Second-order effects
- Security firms and managed-hosting rivals gain a sales opening: every wave like this pushes non-technical owners toward paid services that apply plug-in patches automatically instead of relying on manual updates.
- Plug-in and theme developers come under renewed pressure to ship fixes faster, since unpatched extensions — as SoakSoak showed with RevSlider — become the attack surface for the entire installed base.
Third-order effects
- If the cycle repeats — known vulnerability, slow tail-end patching, mass automated compromise — self-hosting drifts toward managed platforms and hardened distributions, consolidating WordPress deployment around providers who patch centrally rather than millions of individually maintained installs.
- Regulators and payment networks increasingly treat compromised sites as a systemic problem rather than isolated incidents, raising the compliance bar for small operators who cannot demonstrate timely patching.
The trend: WordPress's vast plug-in-dependent install base keeps turning individual unpatched vulnerabilities into industrial-scale malware campaigns, steadily shifting hosting toward centrally patched, managed environments.