Thousands of WordPress websites have been attacked by hackers who aimed to direct visitors to scam websites that included unwanted subscription notifications , fake surveys, giveaway contests , and fake Adobe Flash downloads 
In January 2020, this hacking campaign was noticed by website security company Sucuri, which identified hackers exploiting errors in WordPress links
The most dangerous plugin is “CP Contact Form with PayPal” which concerns methods of communication and payment, with PayPal and “Simple Fields”, i.e. simple fields. However, there are other plugins that are targeted by hackers.
Specifically, the bugs in WordPress websites allow hackers to inject JavaScript that loads scripts from admarketlocation[.] Com and gotosecond2[.] Com directly into the website's theme.
When a user accesses the hacked WordPress site, the injected script will attempt to access the URLs /wp-admin/options-general.php and /wp-admin/theme-editor.php to embed more scripts or change settings , redirecting users to other websites.
However, these URLs require administratorto ensure function .
Once a user agrees to the notifications by clicking the “Accept” button, they will be redirected to scam websites, such as fake surveys, tech support scams, and fake Player .
In addition to injecting JavaScript, Sucuri also found that hackers created fake links that were used to deliver additional malware to targeted websites.
The most common folders presented are: wp-content/plugins/supersociall/supersociall.php and /wp-content/plugins/blockspluginn/blockspluginn.php.
Finally, Sucuri recommends using its free SiteCheck tool to scan users’ websites for malicious content on WordPress websites. So, if a user visits their WordPress site and is concerned that it may have been hacked , SiteCheck will scan the site and highlight any malicious content, while also providing users with help to clean up the “hacked” site.
