CVE-2024-6297
Description
Multiple WordPress plugins were compromised with malicious PHP scripts that exfiltrate database credentials and create admin users; uninstall and scan immediately.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple WordPress plugins were compromised with malicious PHP scripts that exfiltrate database credentials and create admin users; uninstall and scan immediately.
Vulnerability
A supply-chain compromise affected several WordPress plugins hosted on WordPress.org. Malicious PHP scripts were injected into the source code of these plugins, including the "Wrapper Link Elementor" plugin. The injected code exfiltrates database credentials and creates new administrator users with a specific email pattern (e.g., @example.com). The exact list of affected plugins and versions is not fully disclosed, but the compromise impacts any version containing the malicious code prior to its removal.
Exploitation
The attacker gained unauthorized access to the plugin source code repositories and injected the malicious scripts. Once a compromised plugin is installed and activated on a WordPress site, the malicious code executes automatically without requiring additional authentication or user interaction. The code sends database credentials to an external server and creates a new administrator user account with a known email pattern, as seen in the response script that invalidates such users [1].
Impact
Successful exploitation results in full site compromise. The attacker obtains database credentials, enabling direct database access, and creates a persistent backdoor via a new administrator user. This can lead to data theft, site defacement, malware distribution, and further attacks on the server infrastructure.
Mitigation
As of the publication date (2024-06-25), not all affected plugins have been patched. The recommended mitigation is to uninstall any suspected compromised plugins and run a complete malware scan. For the "Wrapper Link Elementor" plugin, a response script has been added to invalidate the malicious admin user and display an admin notice [1]. However, uninstalling and scanning remains the safest course of action until all plugins are patched.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=4.4.6.4
Patches
1r3105893blaze-widgetThis plugin has been removed from the WordPress.org directory on 2024-06-24 (reason: Security Issue). No patched version is being distributed through the official directory. Users who have it installed should uninstall it.
Source: api.wordpress.org · directory page
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- plugins.trac.wordpress.org/browser/blaze-widget/trunk/blaze_widget.phpnvd
- plugins.trac.wordpress.org/browser/contact-form-7-multi-step-addon/trunk/trx-contact-form-7-multi-step-addon.phpnvd
- plugins.trac.wordpress.org/browser/simply-show-hooks/trunk/index.phpnvd
- plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.phpnvd
- plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.phpnvd
- plugins.trac.wordpress.org/browser/wrapper-link-elementor/trunk/wrapper.phpnvd
- plugins.trac.wordpress.org/changeset/3105893/nvd
- plugins.trac.wordpress.org/changesetnvd
- wordpress.org/support/topic/a-security-message-from-the-plugin-review-team/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/56d24bc8-4a1a-4e60-aec5-960703a6058anvd
News mentions
0No linked articles in our index yet.