> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Malvertising Campaign Hides in Plain Sight on WordPress Websites

[SOURCE] Sucuri Blog [AUTHOR: Puja Srivastava] [DATE: 04/10/2025 01:37] [LANGUAGE: EN]
Recently, one of our customers noticed suspicious JavaScript loading across their WordPress website. Visitors were being served third-party scripts that the site owner never installed. After investigation, we discovered the infection originated from a malicious modification in the active theme’s functions.php file. This injected PHP code silently fetched external JavaScript from attacker-controlled domains and inserted it into the site’s front-end. Behind the Breach We found a suspicious script loading on the client’s website. Continue reading Malvertising Campaign Hides in Plain Sight on WordPress Websites at Sucuri Blog.
[messages.read_original_source] →