HomeSecurityWordPress: Backdoor detected in Quick Page/Post Redirect plugin

WordPress: Backdoor detected in Quick Page/Post Redirect plugin

A serious cybersecurity incident has been revealed in one of the most widely used WordPress, Quick Page/Post Redirect, which is installed on more than 70,000 websites worldwide. The plugin, designed to manage redirects on pages, posts, and custom URLs, contained a hidden backdoor that was reportedly built in about five years.

WordPress Quick Page/Post Redirect

The existence of this mechanism raises serious questions about the security of the WordPress plugin ecosystem, but also about how such a critical mechanism went unnoticed for so long.

How the malicious activity was discovered

The discovery was made by Austin Ginder, founder of WordPress hosting company Anchor, when 12 websites he manages triggered security alerts. Analysis of the incidents led to the identification of suspicious behavior in the plugin, which was related to unauthorized code execution.

See also: GitHub fixed critical RCE vulnerability in less than 6 hours

The investigation showed that specific versions of the plugin had deviating behavior compared to the official WordPress.org files, which was the first critical element in uncovering the problem.

Versions 5.2.1 and 5.2.2 and the hidden update mechanism

According to the findings, versions 5.2.1 and 5.2.2 (2020–2021) contained a hidden automatic update mechanism. This mechanism communicated with an external domain, anadnet[.]com , allowing code to be transferred and executed outside of WordPress.org's control.

The worrying element is that this particular mechanism was quietly removed in February 2021 from later versions, before a full technical review by the security community was even completed.

Silent distribution of modified version and backdoor

Even more worrying activity was detected in March 2021. Websites using the vulnerable versions reportedly received a modified version 5.2.3 from an external server with the address w.anadnet[.]com.

See also: Critical authentication vulnerability in cPanel – Update now

Graphican backdoor

This particular version contained a passive backdoor, which is only activated when the user is not logged in, to avoid detection by administrators. In addition, the malicious code connected to the WordPress hook the_content, pulling data from external servers.

Another critical finding was that the files from the external server had a different hash than the official WordPress.org files, confirming the existence of tampering.

SEO spam and search ranking abuse

Ginder described the activity as a form of cloaked parasite SEO, where the infrastructure of 70,000 websites was used to manipulate Google search results. Essentially, the backdoor allowed third parties to “borrow” the credibility of the websites to promote malicious or spammy content.

The current risk and status of the plugin

Although the backdoor mechanism has now been disabled due to a non-functional command server, the plugin still carries the dangerous automatic update mechanism. This means that if the external domain is restored, the threat could be reactivated.

WordPress.org has temporarily removed the plugin from its catalog until a full security assessment is completed.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: CISA: ConnectWise and Windows vulnerabilities in the KEV Catalog

WordPress: Backdoor detected in Quick Page/Post Redirect plugin

Recommendations for webmasters

Experts recommend immediately uninstalling Quick Page/Post Redirect from all websites that use it. As a safe alternative, it is recommended to install a clean version, such as 5.2.4, when it is officially re-released in the WordPress repository.

At the same time, administrators should check for suspicious redirects, unauthorized scripts, and changes to core files.

Wider implications for the WordPress ecosystem

The incident highlights a larger problem: the vulnerability of the supply chain . With tens of thousands of plugins available, even a small security flaw can affect hundreds of thousands of websites.

The case serves as a warning for the need for stricter controls, better transparency in updates, and continuous monitoring of plugin behavior in real time.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS