Blog | G5 Cyber Security

Flaw in defunct WordPress plugin exploited to create backdoor

A vulnerability discovered in the OneTone plugin is now being exploited by hackers to compromise entire sites. Attacks were noticed earlier this month by security company Sucuri. The vulnerability is a cross-site scripting (XSS) flaw that allows attackers to inject malicious JavaScript into the plugins settings. JavaScript is injected via HTML