Over 2,000 WordPress sites have been hacked to fuel a campaign to redirect visitors to scam sites containing unwanted browser notification subscriptions, fake surveys, giveaways, and fake Adobe Flash downloads. This hacking campaign was discovered by website security firm Sucuri who detected attackers exploiting vulnerabilities in WordPress plugins during the third week of January 2020. Sucuri researcher Luke Leak told BleepingComputer that some of the vulnerable plugins seen being exploited are the “CP Contact Form with PayPal” and the “Simple Fields” plugins, but we were told that other plugins are likely being targeted as well.
Source: Bleeping Computer