CVE-2024-6297
Malicious PHP scripts have been secretly embedded into several WordPress plugins hosted on WordPress.org. An unauthorized party gained access to the source code of these plugins and inserted malicious code that siphons off database login credentials, creates rogue administrator accounts, and transmits this information back to an external server. Until all affected plugins are updated with security patches, it's advisable to remove them temporarily and conduct a thorough malware sweep on your system.
Based on public CVE data (MITRE/NVD).