Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on SitesAI
Security

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Attackers compromised JavaScript files used by three popular WordPress plugins (PushEngage, OptinMonster, and TrustPulse), injecting malicious code that created unauthorized admin accounts and installed hidden backdoor plugins when site administrators were logged in. The attack specifically targeted authenticated administrators while leaving ordinary site visitors unaffected, demonstrating a sophi

UTUtopia Tech·1 min
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over SitesAI
Security

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

A critical remote code execution vulnerability (CVE-2026-3300, CVSS 9.8) in the Everest Forms Pro WordPress plugin is being actively exploited by threat actors to compromise websites. The flaw affects all versions up to 1.9.12 of the plugin, which has approximately 4,000 active installations, allowing attackers to execute arbitrary code and achieve complete site takeover.

UTUtopia Tech·1 min
Critical WP Maps Pro Flaw Actively Exploited to Create Admin AccountsAI
Security

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

A critical security vulnerability in WP Maps Pro, a popular WordPress plugin with over 15,000 sales, is being actively exploited by threat actors to create unauthorized administrator accounts on vulnerable websites. The plugin, which enables site owners to embed customizable Google Maps and OpenStreetMap features, presents significant risk to organizations using WordPress for their web presence.

UTUtopia Tech·1 min
Skip to main content