# WordPress Plug-ins Contained Backdoors After Ownership Change

_Tuesday, April 14, 2026 at 4:12 PM EDT · Cybersecurity · Latest · Tier 2 — Notable_

![WordPress Plug-ins Contained Backdoors After Ownership Change — Primary](https://techcrunch.com/wp-content/uploads/2024/09/wordpress-v2.jpg?resize=1200,675)

Dozens of WordPress plug-ins were taken offline after a backdoor was discovered in their source code, allowing malicious code to be pushed to websites using the affected software.

The backdoor was added after a new corporate owner purchased the plug-in maker Essential Plugin last year. According to security researcher Austin Ginder of Anchor Hosting, the backdoor remained dormant until earlier this month before activating to distribute malicious payloads.

Essential Plugin claims over 400,000 plug-in installations across more than 15,000 customers. WordPress data indicates the affected plug-ins were active on over 20,000 websites before being removed from the official directory.

The incident represents a supply chain attack where malicious actors acquire legitimate software companies to compromise their customer base. Plug-ins grant extensive access to WordPress installations, making them attractive targets for such takeovers.

Ginder noted this marks the second WordPress plug-in hijack discovered in recent weeks. Security experts have repeatedly warned about the risks of software ownership changes without user notification, which can expose websites to compromise by new owners.

The affected plug-ins have been permanently removed from WordPress repositories. Website administrators are advised to check their installations for any remaining Essential Plugin components and remove them immediately.

## Sources

- [TechCrunch](https://techcrunch.com/2026/04/14/someone-planted-backdoors-in-dozens-of-wordpress-plugins-used-in-thousands-of-websites/)

---
Canonical: https://techandbusiness.org/newswire/9MKTZ8UxCDmrjzzYMuwHdM
Retrieved: 2026-04-21T10:16:21.599Z
Publisher: Tech & Business (techandbusiness.org)
