Hackers are abusing the “mu-plugins” directory on WordPress websites to hide malicious code, maintain permanent access to target systems, and redirect visitors to fake websites.

mu-plugins (must-use plugins) are plugins in a special directory (“wp-content/mu-plugins”) that are automatically executed by WordPress. They do not require explicit activation via the admin dashboard.
See also: WordPress: The vulnerabilities most used by hackers in Q1 2025
According to Sucuri researcher Puja Srivastava, mu-plugins are not reported in the standard WordPress plugin interface, making it more likely for users to overlook them during routine security checks.
Researchers found three different types of rogue PHP code in the directory:
- “wp-content/mu-plugins/redirect.php“, which redirects website visitors to an external malicious website
- “wp-content/mu-plugins/index.php“, which offers web shell functionality, allowing attackers to execute arbitrary code by downloading a remote PHP script hosted on GitHub
- “wp-content/mu-plugins/custom-js-loader.php”, which injects unwanted content into the infected website, likely to promote scams. It can replace all images on the website and hack outbound links to lead to malicious websites
See also: WP Ghost WordPress: Critical vulnerability puts thousands of sites at risk
According to Sucuri, “redirect.php” disguises itself as a browser update and thus can trick users into installing malware that can steal data or install additional malicious payloads.
“The script includes a function that determines whether the current visitor is a bot,” Srivastava explained. “This allows the script to block search engine crawlers and prevent them from detecting the redirect behavior.”

WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One key strategy includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.
See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
