The widely used WordPress plugin Quick Page/Post Redirect was found to contain a long-hidden backdoor that affected more than 70,000 sites through a covert self-update mechanism outside the normal WordPress.org review process. Researcher Austin Ginder traced the issue to versions 5.2.1 and 5.2.2, which contacted anadnet[.]com and later pulled a tampered 5.2.3 build from w.anadnet[.]com. The malicious code reportedly remained dormant for years and was designed to deliver arbitrary code or injected content to logged-out visitors while hiding activity from logged-in administrators.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
In April 2026, the WordPress plugin review team temporarily removed Quick Page/Post Redirect from the official directory after the backdoor was disclosed. Users were advised to uninstall compromised copies and replace them with a clean 5.2.4 release from WordPress.org once available.
Austin Ginder uncovered the supply-chain compromise after investigating security alerts on 12 infected sites and determined that the plugin had contained a dormant backdoor for years. His analysis found that the remote update mechanism could enable arbitrary code injection and potentially remote code execution if reactivated.
In March 2021, sites running affected versions reportedly received a malicious 5.2.3 update from w.anadnet[.]com. The build added a passive backdoor that hid activity from logged-in administrators while exposing malicious content to visitors and search engine crawlers, likely supporting parasite SEO.
Analysis of the plugin's history indicated that the Quick Page/Post Redirect plugin repository received a hidden self-update mechanism tied to anadnet[.]com in late 2020. This bypassed WordPress.org's normal update review path for versions 5.2.1 and 5.2.2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceanchor.host
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.