Hot Line:

+1 (917) 730-2010

AI-Powered Web Development, SEO, Shopify & WordPress — Get a Free Consultation Today. Get Started

Tutorials

Millions of WordPress Websites Got Hacked Again

  • 21 Apr, 2026
  • 0 Comments
  • By WebSensePro
Millions of WordPress Websites Got Hacked Again

A serious security incident has affected the WordPress ecosystem where 31 plugins were reportedly compromised through a supply-chain attack, exposing millions of websites to potential risk.

One of the confirmed cases includes the “Accordion and Accordion Slider” plugin, which was found to contain an injected backdoor in version 1.4.6.

🔗 Reference:
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/accordion-and-accordion-slider/accordion-and-accordion-slider-146-injected-backdoor

Step 1: Check Your Installed Plugins:

Go to your WordPress dashboard:

Plugins → Installed Plugins

Look carefully for:

  • Accordion and Accordion Slider
  • Any slider, gallery, or UI enhancement plugins
  • Recently updated or unfamiliar plugins

👉 If you find any suspicious plugin, treat it as high risk.

Step 2: Disable and Remove Immediately:

If any affected plugin is installed:

  • Deactivate the plugin
  • Delete it completely
  • Do not wait for updates or fixes

👉 Backdoor-type attacks can remain active even after deactivation.

Step 3: Run a Full Website Scan:

Use a trusted security scanner:

  • Wordfence
  • Sucuri SiteCheck
  • MalCare

Check for:

  • Unknown admin users
  • Suspicious files in wp-content
  • Modified core files
  • Hidden scripts

Step 4: Change All Important Passwords:

Immediately update:

  • WordPress admin login
  • Hosting account
  • FTP/SFTP credentials
  • Database password

👉 Use strong and unique passwords.

Step 5: Check for SEO Damage:

A compromised site may show:

  • Spam pages in Google index
  • Unexpected redirects
  • Ranking drops
  • Suspicious backlinks

Fix using:

  • Google Search Console → Security Issues
  • Remove spam URLs
  • Clean sitemap
  • Request reindexing

Step 6: Secure Your WordPress Site:

After cleanup:

  • Install a firewall plugin
  • Enable 2FA login
  • Limit login attempts
  • Remove unused plugins
  • Keep only necessary tools installed

Final Note:

This incident shows how dangerous third-party plugins can be if compromised. Always keep your WordPress site lightweight, updated, and regularly audited for security risks.

5/5 · 179 votes
Tags:

    Comments

    Background Pattern

    Want to work with us?

    Let’s build your website, grow your traffic, and automate your business with AI.

    Background Pattern