wp-login.php injection silently exfiltrates a victim’s username and password back to the attacker’s server.
A breakdown of how PHP droppers are used to spread binary malware through malicious URLs and spam emails.
A malicious PHP file is used to take down Wordfence plugin before it adjusts its own mtime timestamp.
A payment card skimmer hidden within an existing PNG image on an infected WordPress website that uses MemberPress and collects payment data for private membership. A variant was also found stealing payment card information on an infected Magento website.