Security firms Wordfence and PatchStack have warned WordPress admins about phishing emails that impersonate the legitimate WordPress.com site and trick victims into installing a malicious plugin. The “plugin” reportedly exfiltrates website data, downloads a backdoor and remains hidden on the site’s root directory.

Hackers Upgraded ClickFix Attack With Cache Smuggling to Secretly Download Malicious Files
Cybersecurity researchers have uncovered a sophisticated evolution of the ClickFix attack methodology, where threat actors are leveraging cache smuggling techniques to avoid traditional file download