Wordpress Alert: Compromised third-party plugin updates

An update arrives from an untrusted or compromised distribution channel. Malicious code may be installed as if it were a routine update.

What it looks like

An update arrives from an untrusted or compromised distribution channel.

Why it matters

Malicious code may be installed as if it were a routine update.

What to check

Review plugin provenance and unexpected update behavior.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress hardening guide.