Skip to content
BaeWP

WordPress News & Coverage

Sunday, September 13, 2026
  • Home
Latest WordPress Open Weights AI Letter: What It Means for Site Owners

Tag: PushEngage

Security

Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins

A supply chain attack compromised the CDN-hosted JavaScript SDKs of OptinMonster, TrustPulse, and PushEngage, widely used WordPress marketing plugins. The injected client-side code silently created rogue admin accounts and backdoors by exploiting logged-in administrators' sessions. This incident highlights the risks of third-party CDN dependencies and requires immediate action from WordPress users to audit users, remove backdoors, and harden admin security.

Jul 8, 2026 · 6 min read
Supply Chain Attack

Browse Coverage

  • Community 170
  • Hosting 246
  • Industry 115
  • Jobs 1
  • Security 30
  • WordPress Core 101

Recent Stories

  1. 1 WordPress Open Weights AI Letter: What It Means for Site Owners
  2. 2 Should WordPress Site Owners Install the Official Browser Extension?
  3. 3 WordPress 7.1 Mary Lou Brings Client-Side Media, Responsive Styles, and an AI-Ready Abilities API
  4. 4 How to Evaluate AI Features in WordPress Before Using Them
  5. 5 How to Evaluate AI Features in WordPress Before Using Them

BaeWP

Covering WordPress core, security, hosting, and the ecosystem. Trusted by developers, agencies, and site owners worldwide.

Coverage

  • WordPress Core
  • Security
  • Hosting
  • Industry
  • Community
  • Jobs

Recent

  • WordPress Open Weights AI Letter: What It Means for Site Owners
  • Should WordPress Site Owners Install the Official Browser Extension?
  • WordPress 7.1 Mary Lou Brings Client-Side Media, Responsive Styles, and an AI-Ready Abilities API
  • How to Evaluate AI Features in WordPress Before Using Them
  • How to Evaluate AI Features in WordPress Before Using Them

Info

  • Home
© 2026 BaeWP. All rights reserved. Affiliate Disclosure