Sucuri specialists discover a new Balada Injector campaign targeting vulnerable WordPress websites, exploiting an XSS vulnerability in the Popup Builder plugin and injecting a backdoor disguised as the wp-felody.php plugin, affecting over 1 million sites.
View full story…