A popular WordPress multilingual plugin was hacked by a former employee who sent a mass email warning of security vulnerabilities. read the full blog post at: https://bit.ly/2HGhP6v
The plugin — WPML (or WP MultiLingual) — is a massively popular (+600,000 active installations) paid plugin that's been a "staple" of the WordPress community for some time now.
This is definitely one of the most unique WP plugin vulnerabilities. We're certainly all used to WordPress plugin vulnerabilities at this point, but compromises from within the (former) team are unusual. This is also big news given the popularity and "paid" status of WPML.
On Saturday (Jan 18th, 2018) users of the plugin were sent an unauthorized mass email. In the email, the attacker posed as a security researcher and claimed to have uncovered several critical vulnerabilities within the WPML framework. The attacker also mentioned that he owned several websites that ran WPML and they have been hacked due to the critical vulnerabilities contained within the plugin.
According to the email:
"WPML exposed sensitive information to someone with very little coding skills but merely with access to the WPML code and some interest in seeing how easy it is to break it"
The WPML team was quick to respond. In a quick series of Twitter posts, the WPML team confirmed that the source of the attack was "likely an ex-employee" due to the backdoor/password combo that the attacker used and that the "attacker did not gain access to source code" (which is strange given that WPML's entire plugin is simply code.)
At the same time, WPML admitted that the attack likely accessed customer names, emails, and password information, though they claim that no payment information was stolen. The attack also defaced the WPML WordPress site with a similar message.
WMPL's team is adamant that none of these vulnerabilities exist, though they rebuilt their server from scratch in an attempt to destroy any remaining backdoors.
Kudos to the WPML team for their transparency and rapid response. They handled this situation better than most.