Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
Malicious WordPress Plugin ‘wordpress-player.php’ Redirects Users via Hidden Video and WebSocket C2
Malware and Vulnerabilities
June 19, 2025
sucuri
A new malicious WordPress plugin named wordpress-player.php has been discovered, designed to covertly redirect site visitors to suspicious domains. At least 26 websites have been confirmed as infected, indicating a growing campaign.
Read More
WordPress malware
Fake Plugin
wordpress-player.php
WebSocket C2
Hidden Video Player
Publisher
Previous
Active Exploitation of CVE-2024-3721 in TBK DVRs Enable ...
Malware and Vulnerabilities
Next
North Korean hackers deepfake execs in Zoom call to spr ...
Malware and Vulnerabilities