HomeSecurityWordPress: Hackers abuse mu-plugins for attacks

WordPress: Hackers are abusing mu-plugins for attacks

Hackers are abusing the “mu-plugins” directory on WordPress websites to hide malicious code, maintain permanent access to target systems, and redirect visitors to fake websites.

WordPress mu-plugins hackers attacks

mu-plugins (must-use plugins) are plugins in a special directory (“wp-content/mu-plugins”) that are automatically executed by WordPress. They do not require explicit activation via the admin dashboard.

See also: WordPress: The vulnerabilities most used by hackers in Q1 2025

According to Sucuri researcher Puja Srivastava, mu-plugins are not reported in the standard WordPress plugin interface, making it more likely for users to overlook them during routine security checks.

Researchers found three different types of rogue PHP code in the directory:

  • “wp-content/mu-plugins/redirect.php“, which redirects website visitors to an external malicious website
  • “wp-content/mu-plugins/index.php“, which offers web shell functionality, allowing attackers to execute arbitrary code by downloading a remote PHP script hosted on GitHub
  • “wp-content/mu-plugins/custom-js-loader.php”, which injects unwanted content into the infected website, likely to promote scams. It can replace all images on the website and hack outbound links to lead to malicious websites

See also: WP Ghost WordPress: Critical vulnerability puts thousands of sites at risk

According to Sucuri, “redirect.php” disguises itself as a browser update and thus can trick users into installing malware that can steal data or install additional malicious payloads.

“The script includes a function that determines whether the current visitor is a bot,” Srivastava explained. “This allows the script to block search engine crawlers and prevent them from detecting the redirect behavior.”

WordPress: Hackers are abusing mu-plugins for attacks
WordPress: Hackers are abusing mu-plugins for attacks

WordPress Security

WordPress website security requires a multi-pronged approach to protect against potential threats. One key strategy includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.

See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites

It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS