Researchers at Defiant have discovered a new malvertising campaign that uses vulnerabilities WordPress to infect websites with malware.
Hackers are exploiting known vulnerabilities found in popular WordPress, such as “Coming Soon and Maintenance Mode,” “Yellow Pencil Visual CSS Style Editor,” and “Blog Designer.” These plugins are installed on thousands of websites.
Hackers install a small piece of code , which installs additional malicious code from an external domain and executes it every time visitors browse the compromised site.
The malvertising campaign, identified by the Defiant team, causes unwanted pop-up ads on sites and redirects users to malicious destinations.
Initially, victims are taken to a domain that checks the visitor's device type. The malicious code then redirects them to malicious destinations, which can include tech support scams, sites with malicious Android APKs, and various advertisements.

To carry out the campaign, the hackers used cross-site scripting (XSS) vulnerabilities, which had been identified in Blog Designer and Coming Soon and Maintenance Mode, and an authentication-related issue, which had been identified in Yellow Pencil.
"The Yellow Pencil vulnerability could allow attackers to take complete control of a site," the researchers said.
This particular vulnerability was also used in another hacking campaign in April.
The vulnerability is located in the yellow-pencil.php file and could give the attacker administrator privileges.
Regarding cross-site scripting (XSS) vulnerabilities, most of those detected in this campaign were sent from IP addresses associated with popular hosting providers.
