As many as 1.6 million WordPress sites have been targeted by an active large-scale attack campaign. Four plugins and 15 Epsilon Framework themes have been exploited by 16,000 IP addresses. Wordfence detected and blocked more than 13.7 million attacks aimed at the plugins and themes in a period of 36 hours. Most of the attacks involve the adversary updating the “users_can_register” (i.e., anyone can register) option to enabled and setting the “default_role” setting to administrator.”]
Source: https://thehackernews.com/2021/12/16-million-wordpress-sites-under.html

