
Dormant Backdoor in WordPress Plugin Went Undetected Across 70,000 Sites for Five Years
A malicious code injection hidden in the Quick Page/Post Redirect plugin remained inactive across over 70,000 WordPress sites for five years before discovery in April 2026. The backdoor—dormant until activated by an attacker—allowed remote code execution while evading signature-based security scans and audits. The case illustrates how supply-chain compromises can hide in plain sight when operators choose not to trigger them.
Published