Security researchers have uncovered a sophisticated WordPress malware campaign that exploits the rarely monitored mu-plugins directory to establish persistent backdoors on compromised websites.
The malicious code, discovered in the file wp-content/mu-plugins/wp-index.php, represents a significant evolution in WordPress attack techniques, utilizing database storage and ROT13 obfuscation...