CVE-2024-6297Patch

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-08: 1Active Exploitation · 2026-03-08: 1Patch / Workaround · 2026-03-08: 103-08
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • SudoWP@sudo_wp
    Patch

    1/4 Simply Show Hooks plugin was permanently closed on http://WordPress.org after a supply chain attack (CVE-2024-6297) injected code to create unauthorized admin accounts on affected sites. We forked it from a clean codebase. Here is what changed. https://sudowp.com/blog/the-sudowp-hooks-visualizer-patch/ https://t.co/W9GipvMr4h

    Post summary

    The Simply Show Hooks plugin was decommissioned after a supply‑chain attack that created unauthorized admin accounts; the authors forked a clean codebase and released a patch, linked in the post, to resolve the issue.

    3000049
    5 followersView on X

Explore more