A supply-chain attack hit the Essential Plugin WordPress portfolio after the plugin business was reportedly acquired by a new owner who inserted a hidden backdoor into trusted add-ons used by thousands of websites. Researchers said the malicious code was added to Countdown Timer Ultimate version 2.6.7 in August 2025 as a PHP deserialization backdoor, then left dormant for about eight months before activating in early April 2026. Once triggered, affected sites contacted analytics.essentialplugin.com, received additional payloads, and had malicious code written into wp-config.php.
The compromise allowed attackers to serve hidden spam links, fake pages, and redirects to Googlebot while remaining largely invisible to site owners. WordPress.org subsequently closed all 31 Essential Plugin entries in the plugin directory and pushed version 2.6.9.1 to remove the phone-home behavior, but reports warned that the update did not clean already-compromised wp-config.php files. Hosting providers and researchers urged administrators to manually inspect and remove any still-installed malicious plugins and persistence left on their servers, underscoring the risk that plugin ownership changes can turn established WordPress software into a malware distribution channel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By mid-April 2026, reporting and researcher analysis revealed that dozens of Essential Plugin-associated WordPress plugins used on thousands of websites had been backdoored after an ownership change. The disclosure highlighted the broader risk that WordPress users are not automatically notified when plugin ownership changes hands.
WordPress.org released version 2.6.9.1 to remove the plugins' phone-home mechanism, but the update did not remediate malicious changes already written into compromised wp-config.php files. Site owners were warned to manually inspect and clean infected installations.
On April 7, 2026, WordPress.org shut down all 31 Essential Plugin plugins in the directory and marked them closed following discovery of the compromise. The plugins were removed from distribution to limit further exposure.
On April 5–6, 2026, the hidden backdoor began contacting analytics.essentialplugin.com and delivering malicious code to affected WordPress sites. The malware modified wp-config.php to serve hidden spam links, fake pages, and redirects to Googlebot while staying largely invisible to site owners.
The new owner allegedly inserted a PHP deserialization backdoor into Countdown Timer Ultimate version 2.6.7, with the malicious code then remaining dormant for months across the Essential Plugin portfolio.
A threat actor reportedly purchased the Essential Plugin WordPress plugin business from founder Minesh Shah via Flippa, setting up a supply-chain compromise through a trusted plugin portfolio.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceanchor.host
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.