Home InternationalCompromised WordPress Sites Deliver ClickFix Attac...
International⭐ Featured

Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign

Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers

6 April 2026 at 02:42 pm
1 views
Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign

In a recent global cybersecurity threat, over 250 legitimate WordPress websites, including prominent news outlets and even a US Senate candidate’s official webpage, have been compromised to deliver infostealer attacks. Rapid7, a cybersecurity research firm, has warned of this widespread campaign, highlighting the vulnerabilities in WordPress that attackers are exploiting to infect visitors with malicious software.

The attack, dubbed "ClickFix," involves injecting malicious code into WordPress websites, which then tricks users into downloading and installing infostealers on their devices. Infostealers are a type of malware designed to collect sensitive information, such as login credentials, financial data, and personal details, often without the user’s knowledge. The compromised websites appear legitimate to users, making it difficult to detect the threat until it is too late.

Rapid7’s analysis reveals that the attackers are exploiting a known vulnerability in WordPress, specifically CVE-2023-23300, which was patched in March 2023. This suggests that many of the affected websites may not have updated their WordPress platforms promptly, leaving them vulnerable to exploitation. The campaign has been ongoing for several months, with new websites falling victim as attackers continue to refine their tactics.

The impact of this infostealer campaign is significant, as it not only affects individual users but also compromises the integrity of reputable organizations. The US Senate candidate’s official webpage being targeted underscores the potential for political interference and the theft of sensitive campaign data. News outlets, which are trusted sources of information, can be used to spread disinformation or further manipulate public opinion through the distribution of malicious content.

Rapid7 has urged WordPress site administrators to take immediate action to secure their platforms. This includes updating WordPress and all plugins and themes to the latest versions, ensuring that all security patches are applied, and implementing strong passwords and two-factor authentication. Additionally, using a web application firewall and monitoring tools can help detect and prevent further attacks.

The global reach of this campaign highlights the ongoing challenges in cybersecurity, particularly for small businesses and individuals who may lack the resources to adequately protect their WordPress sites. It is crucial for website owners to prioritize security measures and stay informed about the latest vulnerabilities and threats.

As Rapid7 continues to track the spread of this infostealer campaign, it serves as a reminder of the importance of proactive cybersecurity practices. Organizations and individuals must be vigilant in safeguarding their digital presence, as attackers will continue to exploit vulnerabilities to gain access to sensitive information and disrupt operations.

In conclusion, the compromised WordPress sites delivering ClickFix attacks in a global infostealer campaign underscores the critical need for robust cybersecurity measures. By updating software, monitoring for vulnerabilities, and implementing strong security practices, website administrators can mitigate the risks and protect their users from malicious attacks. The involvement of high-profile targets, such as a US Senate candidate and news outlets, emphasizes the potential for widespread damage and the necessity for continuous vigilance in the digital realm.

📰 Related News
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 is now live, featuring native support for Google's Gemma 4 models and improved local inference performance for Windows, macOS, and Linux.
14 Apr
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Below are the most-read DIGITIMES Asia stories from the week of April 6-April 13, 2026:
14 Apr
cutile-stencil 0.2.0
cutile-stencil 0.2.0
An xDSL-based stencil compiler that generates optimized GPU kernels via NVIDIA cuTile
14 Apr
merlin-llm added to PyPI
merlin-llm added to PyPI
Merlin — a fast local LLM for agentic coding on Apple Silicon
14 Apr
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Craft and compose videos programmatically in PHP with an elegant fluent API - b7s/fluentcut
14 Apr
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Justin Sun has accused Trump-affiliated World Liberty Financial of misconduct and a general lack of transparency.
14 Apr
nvidia-nat-weave 1.7.0a20260413
nvidia-nat-weave 1.7.0a20260413
Subpackage for Weave integration in NeMo Agent Toolkit
14 Apr
nvidia-nat-s3 1.7.0a20260413
nvidia-nat-s3 1.7.0a20260413
Subpackage for S3-compatible integration in NeMo Agent Toolkit
14 Apr
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Six years. That is how much time separates retirees from a Social Security system that, by its own projections, runs out of money. If you are 56 years old...
14 Apr
cane-gpu-perf added to PyPI
cane-gpu-perf added to PyPI
GPU inference benchmarking with opinionated diagnostics
13 Apr