Home » Security News » Thousands of WordPress websites have been hacked t...

Thousands of WordPress websites have been hacked to redirect users to scam pages

Thousands of WordPress websites have been hacked to redirect users to scam pages

Add Techlomedia as a preferred source on Google. Preferred Source

Cybersecurity researchers at Sucuri have discovered a massive JavaScript Injection Campaign against WordPress websites that redirects users to spam web pages. In this attack, malicious JavaScript code has been injected into several WordPress websites. This code redirects visitors to scam pages.

In this attack, legitimate JS files such as jquery.min.js and jquery-migrate.min.js were altered to inject malicious codes. Malicious codes have been injected into files and databases. Once the code has been injected, it starts redirecting visitors.

Attackers are targeting multiple vulnerabilities in plugins and themes to compromise websites and inject malicious scripts. If you also use WordPress, it is recommended to always keep themes and plugins updated. Attackers have also obfuscated their malicious JavaScript with CharCode to evade detection.

These redirects are used to load advertisements, phishing pages, malware, or even more redirects.

If your website is also redirecting users to random web pages, you can use remote website scanners like SiteCheck to scan and identify malware on your website.

It is not clear how many websites have been infected by this campaign, but PublicWWW estimates that the campaign was responsible for nearly 6,000 infected websites alone. PublicWWW only shows detections for simple script injections, the overall affected websites could be more.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.