A Russian malware called SoakSoak has infected over 100,000 Wordpress sites since this Sunday, turning blogs into attack platforms. It's a potential shitshow, and it could've been prevented earlier this fall.
Google has already blocked 11,000 domains to try to curb the damage. According to security firm Sucuri, the malware uses a vulnerability in a slideshow plug-in called Slider Revolution. The Slider Revolution team has known about the vulnerability since September, but it looks like they failed to fix it before the security hole got crammed with steaming hot malware.
Researchers at
Sucuri are warning that it'll be hard to completely eradicate the malware as long as so many site owners don't know it's there. In addition to removing the malicious code, they will need to update the premium plug-in. If the plug-in came as part of a theme, it won't update automatically, which means site admins will have to manually update.