PhishWP Plugin Compromises WordPress E-Commerce Checkout Security

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

New Malicious WordPress Plug-In Turns E-Commerce Sites into Phishing Pages: The Rise of PhishWP

PhishWP: Malicious WordPress Plugin Turns E-Commerce Sites into Phishing Machinery

Cybersecurity researchers have uncovered a malicious plugin dubbed "PhishWP" that is exploiting WordPress sites to create sophisticated phishing pages that masquerade as reliable online payment processes. Discovered on a Russian cybercrime forum, the plugin targets unsuspecting customers by mimicking trusted e-commerce applications like Stripe, effectively siphoning sensitive payment information from users.

According to findings published by SlashNext this week, PhishWP is designed to be highly deceptive, incorporating features that allow it to duplicate legitimate payment flows. Notably, it generates one-time passwords (OTPs) during transactions, enhancing the illusion of security and trustworthiness. Victims, believing they are engaging with a legitimate payment gateway, unwittingly enter their credit card details, expiration dates, and CVVs, only for this sensitive information to be transmitted directly to a Telegram account controlled by cybercriminals.

SlashNext security researcher Daniel Kelley highlighted how PhishWP’s counterfeit checkout pages can look remarkably authentic, causing users to feel confident in their transactions. The plugin not only captures payment information but also gathers additional data such as IP addresses and screen resolutions, creating detailed profiles for future fraudulent activities.

Further complicating prevention efforts, PhishWP can be easily installed on either compromised legitimate sites or entirely fraudulent ones. Its capacity for auto-generating fake order confirmations extends the window of deception, allowing attackers to delay detection until it’s too late.

As cybercriminals increasingly turn to malicious WordPress plugins, the potential for devastation grows. SlashNext advocates for browser-based phishing protection solutions to combat such threats, offering users a vital line of defense against these evolving tactics.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

China’s Foreign Ministry Responds to Anthropic CEO’s Call for AI Development Restrictions

China’s Ministry of Foreign Affairs has responded to a call from Anthropic CEO Dario Amodei for the U.S. to impose restrictions on China's artificial...

Passkey-themed social engineering attacks lead to identity and cloud compromises, warns Microsoft Security

Microsoft Security Research is tracking active cloud-based intrusions that have led to identity and cloud compromises. These attacks typically begin with unusual sign-ins followed...

Nightspire Ransomware Claims Attack on UAE’s DiamondLease, Demands Negotiations

Nightspire Ransomware Targets UAE's DiamondLease, Demands Negotiations On September 11, 2026, the ransomware group Nightspire publicly claimed responsibility for a cyberattack against DiamondLease, a leading...

Research Reveals Root Access Can Enable Identity Spoofing in SPIFFE/SPIRE on Kubernetes

Executive Summary Recent research from Palo Alto Networks' Unit 42 has unveiled critical vulnerabilities in the Secure...