Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access post, maart 6, 2025maart 10, 2025 Over 1,000 websites powered by WordPress have been infected with a third-party JavaScript code that injects four separate backdoors. “Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed,” c/side researcher Himanshu Anand said in a Wednesday analysis. The malicious JavaScript code has been found to be served via cdn.csyndication[.]com. As of writing, as many as 908 websites contain references to the domain in question. Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access: Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access vulnerability 2025