Silent Invasion: New WordPress Malware Exploits Hidden Plugin Feature to Hijack Sites

Listen to this Post

Featured Image

A New Threat Lurking Beneath the Surface

In a rapidly evolving digital landscape, even well-established platforms like WordPress are not safe from stealthy intrusions. Security researchers have recently uncovered a sophisticated malware campaign that abuses a little-known feature of WordPress — the Must-Use (MU) plugins directory. This exploit allows attackers to maintain silent, persistent access to WordPress sites while dodging conventional security measures. What makes this technique especially alarming is its stealth, resilience, and automated reactivation, even after apparent cleanup. It’s a quiet but deadly takeover mechanism that could leave thousands of websites exposed if not properly addressed.

The Hidden Backdoor That Refuses to Close

Security experts have flagged a new malware strategy that targets WordPress sites by leveraging the mu-plugins directory — a special folder designed for Must-Use plugins that WordPress loads automatically and cannot be disabled through the admin interface. At the heart of this attack is a disguised file named wp-index.php, which operates as a stealthy loader. It uses ROT13 obfuscation, a basic letter-shifting cipher, to hide a remote URL that serves malicious content. Though the cipher is simple to decode, it successfully avoids detection by most casual scans.

Once the malicious script is activated, it retrieves a base64-encoded payload and stores it temporarily inside the WordPress database under a hidden option key. It then writes this payload to a PHP file in the uploads folder, executes it, and deletes it within seconds — leaving almost no forensic trail. Analysis of the payload, found in a remote cron.php file, revealed a full malware framework, complete with a secret file manager script hidden in the theme directory. This script gives hackers full access to the file system and is protected by a hardcoded HTTP token for authentication.

The attack doesn’t stop there. The malware creates a new admin user called officialwp, then resets passwords of common admin usernames like admin, root, and wpsupport, essentially locking legitimate users out. This backdoor ensures attackers retain access even after password changes. The malware also installs a rogue plugin (wp-bot-protect.php) that acts as a self-healing mechanism, reactivating the infection if it’s partially removed.

With admin-level access, hackers can insert more malware, leak sensitive information, deface content, or even enlist the infected website into a botnet for wider attacks. This multi-stage strategy combines persistent access via mu-plugins, hidden code in the database, silent execution, and aggressive defense mechanisms to evade cleanup. Website owners are now urged to audit mu-plugins, scan for unusual users or database entries, and stay vigilant against even minor anomalies. Without proactive steps, this undetectable menace could quietly compromise countless WordPress installations.

What Undercode Say:

The Technical Anatomy of the Exploit

This campaign represents a fusion of old-school obfuscation with modern persistence tactics. The use of ROT13 is rudimentary yet effective against superficial scans, giving the attackers a deceptive cloak. But the real sophistication lies in leveraging WordPress’s own mu-plugin architecture — a rarely monitored space — as a permanent foothold. Once inside, the malware dynamically writes and erases itself, performing operations so quickly that most forensic tools would miss them.

Obfuscation and Anti-Forensics

The attackers use multiple evasion techniques: from base64 payloads stored in the database to near-instant deletion of executed scripts. These efforts aim to defeat traditional file-based malware scans. Even if an admin removes suspicious files, the malware can rebuild itself using database triggers or rogue plugins that act as fail-safes.

Admin User Hijacking

The automatic creation of the officialwp user and forced password resets of other admin accounts mark a brutal takeover strategy. It’s not just about infecting a system — it’s about owning it permanently. This method turns a compromised WordPress site into a fully hijacked environment where legitimate admins lose control.

Rogue Plugin Reinforcement

The deployment of wp-bot-protect.php serves a dual purpose: it acts both as a secondary backdoor and as a regenerative node that ensures survival. This mirrors tactics used in advanced persistent threats (APTs), where attackers deploy multiple backdoors to ensure that no single removal action can fully cleanse the system.

Persistence via Unseen Channels

By embedding malicious operations in Must-Use plugins — which most administrators never audit — and disguising traffic via ROT13, the malware can quietly live off the land, blending into normal WordPress functionality. It sidesteps both plugin audits and admin dashboards, making it incredibly hard to spot.

Implications for the WordPress Ecosystem

This campaign signals a shift in malware strategy. Attackers are no longer focused on immediate defacement or spam injection. Instead, they aim for long-term infiltration, enabling them to extract data, manipulate user accounts, and extend their control silently. It’s a harbinger of more complex, layered attacks coming to open-source platforms.

Countermeasures and Recommendations

Administrators must act fast. Immediate steps should include:

Manually checking the `/mu-plugins/` directory

Reviewing the user list for unauthorized admin accounts

Scanning the database for unknown options like `_hdra_core`

Monitoring access logs for suspicious activities or token-authenticated requests

Security plugins alone won’t be enough. Manual audits, database integrity checks, and proactive monitoring of obscure WordPress features are essential in this new threat landscape.

Broader Security Implications

This breach strategy can be repurposed for other CMS platforms that rely on similar plugin or module loading features. It’s a template for future malware frameworks — discreet, durable, and designed for long-term persistence.

🔍 Fact Checker Results:

✅ Verified: MU-Plugins are loaded automatically and cannot be disabled via the dashboard
✅ Verified: ROT13 obfuscation and base64 payload storage were used in the described malware
✅ Verified: Malware creates a new admin user and installs a secondary self-healing plugin

📊 Prediction:

🛡️ Expect more malware campaigns in 2025 to leverage low-visibility plugin paths like mu-plugins, especially on outdated WordPress installations
🧠 Attackers will adopt multi-layered persistence tactics that integrate file, database, and user-level hijacking to extend control
⚠️ CMS security tools will need to evolve with deeper scanning capabilities for non-standard directories and obfuscated database entries

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin