News
A new malware threatens the security of WordPress
Un administrador oculto permite a los atacantes de WordPress obtener el control total

- July 25, 2025
- Updated: July 25, 2025 at 7:33 AM

Cybersecurity researchers have revealed a serious vulnerability in WordPress sites, related to a hidden backdoor in the ‘mu-plugins’ directory. These types of plugins, known as must-use, are automatically activated in all WordPress installations and do not appear in the usual plugin list, making them an attractive target for attackers.
What to do to avoid it
The malicious PHP script, discovered by the web security company Sucuri, acts as a loader that retrieves a remote payload and stores it in the WordPress database. This payload allows for remote PHP code execution, facilitating persistent access for attackers, who can manage files and reinstall the infection if it is removed.
The malware injects a hidden administrator user called ‘officialwp’, allowing attackers to control the site and perform malicious actions without other administrators being aware. Additionally, the malicious code has the ability to change the passwords of administrative accounts to a default value, blocking access to other administrators and ensuring total control of the site.
The threat is amplified by the ability of the malware to steal data and redirect visitors to fraudulent sites, which significantly impacts web security. According to experts, this backdoor allows attackers to perform a variety of actions, from installing more malware to defacing the site.

To mitigate these risks, site owners must periodically update WordPress, themes, and plugins, use two-factor authentication, and regularly audit all sections of the site, including theme and plugin files. Maintaining security is crucial to prevent attacks that could compromise the integrity and trust of the website.
Latest from Agencias
- There is only a month and a half left to say goodbye to one of the animes that have marked the decade
- The director of 'The Marvels' is very clear about why it failed
- Marvel recorded all the scenes with one of the actors from Black Widow, and he ended up completely fed up
- He was about to win the Oscar this year. Now he returns with Colin Farrell in one of the best trailers of the season
You may also like
- News
There is only a month and a half left to say goodbye to one of the animes that have marked the decade
Read more
- News
The director of 'The Marvels' is very clear about why it failed
Read more
- News
Marvel recorded all the scenes with one of the actors from Black Widow, and he ended up completely fed up
Read more
- News
He was about to win the Oscar this year. Now he returns with Colin Farrell in one of the best trailers of the season
Read more
- News
This indie game has been on sale for less than two weeks and is already one of the most critically acclaimed games of the year
Read more
- News
One of the best James Bonds in history wants to return in the new agent movie
Read more