PhishWP, a recently discovered WordPress Plugin , is being used by cybercriminals to turn legitimate websites into phishing traps, putting user data at risk
See also: WordPress WPLMS: Plugins vulnerable to critical vulnerabilities

Cybercriminals have created the WordPress plugin PhishWP. It creates fake payment pages that closely resemble legitimate providers like Stripe. Threat actors use it to steal sensitive data, including browser metadata, credit card details, and personal information.
Additionally, PhishWP integrates with Telegram, allowing attackers to access stolen data as soon as the victim presses “enter.” This increases the speed and effectiveness of phishing attacks.
Attackers can either compromise legitimate WordPress sites or create fraudulent websites to install PhishWP. Unknowing users are tricked into providing payment information after the plugin is configured to look like a payment gateway.
PhishWP creates incredibly realistic fake interfaces by simulating payment processors like Stripe with customizable checkout pages.
Through skillfully crafted phishing emails , social media ads, or misleading search results, victims find their way to the website.
See also: RCE vulnerability in 1,000,000 WordPress sites allows backend control

After entering payment and personal data, WordPress PhishWP immediately sends all sensitive information, including addresses, credit card details, and even unique security codes, to the attacker, usually via Telegram.
A fake confirmation email is then sent to the victim, making them feel like their transaction was successful. Meanwhile, the attacker sells or uses the stolen data on underground online marketplaces.
3DS is a security feature that sends a short code to a user's phone or email to verify that they are the real cardholder. By obtaining this code, attackers can impersonate users and make their fraudulent transactions appear completely legitimate.
It stops sending fake order confirmations to victims, delaying suspicion and detection. It also supports multiple languages, allows for global phishing campaigns, and offers source code for more advanced customizations or a obfuscated version of the plugin for stealth.
To mimic user interfaces for future fraud, it records information including IP addresses, screen resolutions, and user agents.
See also: 390,000 WordPress accounts stolen by hackers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
WordPress plugins are essential tools that extend the functionality of websites, but not all of them are created with good intentions. Malicious WordPress plugins, such as PhishWP, can pose significant threats , such as data breaches, unauthorized access, and malware distribution. These plugins are often disguised as legitimate, luring users with attractive features while secretly exploiting vulnerabilities. To protect a website, it is important to download plugins only from trusted sources, keep them up-to-date, and regularly check installed plugins for any suspicious activity. Proactive security measures and vigilance are key to avoiding the potential risks posed by malicious plugins.
Source: cybersecuritynews
