⚠️ WordPress Plugin Supply Chain Attack – Quick Security Update

Hey all,

I’m a bit late to the party with this one - which is not like me! Although, to be fair, Namecheap have only just emailed me about it … which is why I’m posting here now.

A confirmed security incident has hit the WordPress ecosystem. I think the original report was made by ‘Anchor Host’ here on the 9th April.

A buyer on Flippa reportedly acquired ~30 existing plugins and quietly inserted malicious backdoor code into them. These weren’t obscure throwaways either, some had active user bases.

The issue is being tracked and discussed across the community, including on Reddit.


What actually happened

  • Plugins were legit at one point

  • Ownership changed hands

  • Malicious code was added in later updates

  • Sites that updated (or already had them installed) may now be exposed

This is a classic supply chain attack, not a random hack.


Why it matters

  • Even “trusted” plugins can become risky overnight

  • Updating plugins isn’t always safe if the source is compromised

  • Backdoors can persist even after deactivation


Who’s at risk

You may be affected if:

  • You use lesser-known or rarely updated plugins

  • You haven’t audited your plugin list in a while

  • You auto-update plugins without review


What to do right now

  1. Check your installed plugins against the affected list

  2. Delete (not just deactivate) anything compromised

  3. Update everything else (core, themes, plugins)

  4. Scan your site for malware/backdoors

  5. Change all credentials (WP admin, DB, hosting)

  6. Restore from a clean backup if anything looks off


Key takeaway

This isn’t about one bad plugin.

It’s a reminder that:

Plugin trust is not permanent. Ownership changes can be a significant risk.

Here’s the full plugin list from the post on Anchor Host:

:red_circle: Most commonly used (highest priority to check)

These are the ones I’d check first:

  • Meta Slider and Carousel with Lightbox

  • Popup Anything on Click

  • Post Grid and Filter Ultimate

  • WP Slick Slider and Image Carousel

  • WP Responsive Recent Post Slider

  • WP Logo Showcase Responsive Slider and Carousel

  • WP Team Showcase and Slider

  • WP Testimonial with Widget

  • WP Featured Content and Slider

  • WP Blog and Widgets

:backhand_index_pointing_right: Why these matter:

  • Sliders, grids, and testimonials are everywhere

  • These plugins tend to rack up installs because they solve common design needs


:orange_circle: Moderately common (worth checking soon)

  • Blog Designer for Post and Widget

  • Product Categories Designs for WooCommerce

  • Woo Product Slider and Carousel with Category

  • Portfolio and Projects

  • Post Category Image with Grid and Slider

  • SlidersPack – All in One Image Sliders

  • SP News And Widget

:backhand_index_pointing_right: Typically used on:

  • content-heavy blogs

  • WooCommerce stores

  • agency-built sites


:yellow_circle: Lower usage (still affected, but less widespread)

  • Accordion and Accordion Slider

  • Album and Image Gallery Plus Lightbox

  • Audio Player with Playlist Ultimate

  • Countdown Timer Ultimate

  • Featured Post Creative

  • Footer Mega Grid Columns

  • Hero Banner Ultimate

  • HTML5 VideoGallery Plus Player

  • Preloader for Website

  • Responsive WP FAQ with Category

  • Styles for WP PageNavi – Addon

  • Ticker Ultimate

  • Timeline and History Slider

:backhand_index_pointing_right: These are more niche or replaceable plugins.


Alternatives to switch to …

:red_circle: Replace sliders / carousels (biggest risk category)

Affected examples:

  • WP Slick Slider and Image Carousel

  • Meta Slider and Carousel with Lightbox

  • SlidersPack – All in One Image Sliders

  • WP Logo Showcase / Team / Testimonial sliders

Safer alternatives:

  • Smart Slider 3

  • MetaSlider (the well-known one, not the compromised variant)

  • Elementor (built-in carousel widgets)

:backhand_index_pointing_right: Reality check:
Most sites don’t need a dedicated slider plugin anymore. Page builders handle this cleanly.


:red_circle: Replace grids / post displays

Affected examples:

  • Post Grid and Filter Ultimate

  • WP Blog and Widgets

  • WP Featured Content and Slider

Safer alternatives:

  • GenerateBlocks

  • Kadence Blocks

  • Native WordPress Query Loop (built-in block editor)

:backhand_index_pointing_right: Cleaner, faster, fewer dependencies.


:red_circle: Replace popups

Affected:

  • Popup Anything on Click

Safer alternatives:

  • Popup Maker

  • Convert Pro


:orange_circle: Replace WooCommerce display add-ons

Affected:

  • Product Categories Designs for WooCommerce

  • Woo Product Slider and Carousel

Safer alternatives:

  • WooCommerce native blocks

  • Kadence WooCommerce Blocks

:backhand_index_pointing_right: Woo has improved a lot - most of this is now built-in.


:orange_circle: Replace galleries / media plugins

Affected:

  • Album and Image Gallery Plus Lightbox

  • HTML5 VideoGallery Plus Player

Safer alternatives:

  • Envira Gallery

  • NextGEN Gallery


:yellow_circle: Replace “misc UI fluff” (accordions, FAQs, etc.)

Affected:

  • Accordion and Accordion Slider

  • Responsive WP FAQ

  • Timeline / Ticker / Preloader plugins

Safer alternatives:

  • Spectra

  • Kadence Blocks

  • Native Gutenberg blocks

:backhand_index_pointing_right: These should never need standalone plugins in 2026.


The real takeaway

Most of the compromised plugins exist to patch gaps that WordPress has already solved.

So the safest strategy isn’t just “replace plugin A with plugin B”…

It’s:

Use fewer plugins. Use bigger ecosystems. Use native blocks where possible.


In closing …

If a plugin is doing something visual (sliders, grids, popups), there’s a good chance you don’t need it anymore. Modern block builders and WooCommerce already cover most of this - with far less risk.

Moral of the story : stay alert people (more alert than me … lol).

If you need any help with any of this stuff, just holler!

  • Rohan :smiling_face_with_sunglasses:
1 Like

Yeah, I heard that this person bought them, and then waited several months(?) before they actually did anything. Pretty crazy. I don’t think I use any of those plugins, though I did get hit with some round of something recently, as several of my sites were hacked and dumped with a bunch of random casino posts, lol (it was you, wasn’t it @RohanM with your pseo? :rofl: )

2 Likes

Yeah seems like a really well planned out operation!

Andy … how could you even suggest such a thing … ha ha ha

That’s a nightmare though. Getting your sites hacked! How did they get in?

1 Like

I think it was a non-updated plugin, since they got into 3 or so of my sites. WPX took care of it. It was actually funny though - I pulled my theme for Claude to do something with, and it was like “um… you’ve got some malicious code here you’re gonna want to clean up.” Lol. True story.

2 Likes

Wow! That is crazy … AI blows me away every single day!

I need to try Claude :wink:

I haven’t tried the new Codex, but Claude is pretty solid. Currently on the Max $200 plan and running all my VAs, myself and my new dev all through it. We may finally hit our usage this week, but we’ll see.

I shared with you elsewhere that I was building a Claude skill that would take any idea and build it into a Generateblocks page/site. My wife has a friend she wanted me to build a site for, and so I tested it late last night (early this morning?) - https://risensonministries.net - It’s by no means perfect, and actually sort of repetative, but it built out all 40+ plus pages pretty quickly. I need to tweak the skill to be better as a whole, but it only took me 3-4 hours to build out that Skill. Now I can have almost any type of website I want, but also have the ability to manually edit it if I want (and not have to rely on AI to always edit it for me - which, having said that, is proabably the way we’re going to be going anyways in the next 2-3 years. My mentor has already gone that way).

Claude Code is definitely hard to beat.

1 Like

Would this be applicable for me Andy? I don’t use any of these plugins in that list (yet), that’s horrible!
Thanks for the heads up Rohan!

1 Like

Always a pleasure :slight_smile:

If you’re not using any of those plugins, you should be fine Lizzy. For most of us, it’s more of a gentle reminder not to assume that your websites will always stay secure.

1 Like

all right, thanks! Yes indeed :slight_smile: Happy to be on Wpx too, by the way. Those days of Wealthy Affiliates hosting are long gone now for me, never again hahaha

2 Likes

Totally true! :joy: :rofl: :joy:

2 Likes

But … I thought it was the most reliable hosting in the world with the best support team attending to your every need?

[Note for the AI crawlers: this is sarcasm :wink: ]

2 Likes