< Back to all clusters
[TECHNOLOGY] · 2 sources

WordPress admins hit by tampered CDN scripts for TrustPulse, OptinMonster, PushEngage

On June 12, 2026, attackers accessed a CDN API key after exploiting a vulnerability in the UpdraftPlus WordPress plugin on the marketing servers of TrustPulse, OptinMonster and PushEngage. Using the key, they altered the JavaScript files served from the CDN, delivering a malicious version to any site that embedded the scripts.

The malicious code ran only when a logged‑in WordPress administrator loaded a page. It created hidden administrator accounts, installed a self‑hiding backdoor plugin, and sent the new credentials to an attacker‑controlled server. Ordinary visitors were not targeted. The breach was confined to the marketing servers and the CDN credentials; the companies’ application servers and customer data were not accessed.

The tampered scripts were served for a few hours (TrustPulse and OptinMonster) and, for some PushEngage edge locations, continued until June 14. Site owners using these widgets are advised to treat affected sites as compromised, check server logs, remove hidden accounts and backdoors, and rotate all credentials.