
WordPress Plugin Backdoor Lay Hidden for Five Years Across 70,000 Sites
The Quick Page/Post Redirect plugin, active on over 70,000 WordPress installations, contained injected malicious code for five years without detection. The dormant backdoor allowed arbitrary code injection into compromised sites. The discovery, reported in April 2026, exemplifies how supply-chain attacks can survive signature-based detection and routine audits by remaining quiet until activated by the operator.
Published