• Home
  • About
  • Services
    • Web Development
    • Digital Marketing And SEO
    • WordPress Security & Performance
  • Clients
  • Contact Us
  • Speak with us
  • Menu Menu

Display Widgets WordPress Plugin contains Malicious Code to Publish Spam

September 15, 2017/in Industry News, WordPress/by Vinay Bansal

If you have a plugin called “Display Widgets” on your WordPress website, remove it immediately. The last three releases of the plugin have contained code that allows the author to publish any content on your site. It is a backdoor.

The authors of this plugin have been using the backdoor to publish spam content to sites running their plugin. During the past three months the plugin has been removed and readmitted to the WordPress.org plugin repository a total of four times. The plugin is used by approximately 200,000 WordPress websites, according to WordPress repository. During the past months you would have been warned several times that this plugin has been removed with a ‘critical’ level warning from the WordPress repository.

It turns out that this plugin did have “unknown security issues”. Let’s start with a timeline of what happened to Display Widgets, why it was removed three times from the repository and allowed back in each time and then finally removed again a fourth time a few days ago.

The malicious code is not an exploit. It is a backdoor giving the author access to publish content on websites using the plugin. Thanks to the active WordPress community that have immediately informed WordPress and they removed this plugin immediately from the repository.

Could This Have Been Accidental?

It is worth considering that the plugin author may have accidentally included an external library that contained someone else’s malicious code without realizing it. As per our recent study, it was deliberate and done by the new owner of the plugin who purchased from the original author a few months back.

We shall be releasing a video blog with more inspection and will go into root of this breach. Please keep an eye.

 

Share this entry
  • Share on Facebook
  • Share on X
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.dreamdax.com/wp-content/uploads/2017/09/wordpress-security.jpg 320 495 Vinay Bansal https://www.dreamdax.com/wp-content/uploads/2021/05/dreamdax-logo2021-1.svg Vinay Bansal2017-09-15 18:04:422021-05-31 16:45:09Display Widgets WordPress Plugin contains Malicious Code to Publish Spam

CATEGORIES

  • Industry News
  • IT Infrastructure
  • Open Source Framework
  • WordPress

Join these great brands today

We are proud to have earned the trust of so many clients over the past many years. A trust on a total commitment to quality solutions that deliver high-impact results. The fact is, we love to make our customers the HEROES.

 
PreviousNext

Newsletter

This field is for validation purposes and should be left unchanged.

IT solutions, leveraging industry leading technologies to drive real business results for clients.

Latest from our blog

  • WordPress 5.8 Launches Today With Powerful New CapabilitiesJuly 21, 2021 - 11:28 am
  • Security and Maintenance Release from WordPress as Version 5.1.1March 13, 2019 - 9:56 am
  • Display Widgets WordPress Plugin contains Malicious Code to Publish SpamSeptember 15, 2017 - 6:04 pm
  • Gutenberg and the buzzword around it…September 5, 2017 - 5:03 pm

Contact Us

Registered Address: 481, Sanskriti Apartments, Sector 19B, Dwarka, New Delhi – 110075, India

Operations: 4TH Floor, Plot #94, Sector-13, Dwarka, New Delhi -110078, India.

Call: +91 981-140-1177
Email: info@dreamdax.com

Schedule a call to speak with one of our representatives today!

Schedule a call

© Copyright 2026 | Privacy & Terms | Blog | Career | Discovery Forms

  • Facebook
  • Twitter
  • LinkedIn
  • Skype
Gutenberg and the buzzword around it…Security and Maintenance Release from WordPress as Version 5.1.1
Scroll to top