Table of Contents
ToggleA cybercriminal group accidentally left one of its own servers open to the internet without a password. Security researchers discovered the server and found hacking tools, target lists, and activity logs that revealed how the group was attacking websites.
The server contained information about more than 1.4 million websites that had been scanned for vulnerabilities. Fortunately, this does not mean all of these websites were hacked, but it shows how large the operation was.
How the Attack Worked
The attackers weren’t using new or unknown security flaws. Instead, they searched for websites running outdated WordPress plugins with vulnerabilities that had already been fixed by developers.
The most targeted plugins included Breeze Cache and ThemeREX Addons, which were used to compromise thousands of websites that had not been updated.
Researchers estimate that more than 25,000 websites were successfully compromised during the campaign.
How to Protect Your WordPress Website
The best way to stay safe is to keep WordPress, your plugins, and your themes up to date. If you use plugins such as Breeze Cache, ThemeREX Addons, Simple File List, or WP File Manager, make sure you are running the latest version.
It’s also a good idea to remove plugins you no longer use, regularly scan your website for malware, and keep backups of your site. You can also check whether your plugins have known security issues using the WPScan Vulnerability Database.
Conclusion
This incident is a reminder that most WordPress attacks succeed because websites are not updated in time – not because hackers discover new vulnerabilities.
Keeping your website updated and regularly checking its security are the easiest and most effective ways to protect your business.
Need Help Securing Your Website?
If you’re not sure whether your WordPress website is secure, the team at DITS.agency can help. We provide WordPress security audits, malware checks, plugin reviews, and practical recommendations to help keep your website safe from cyberattacks.


