📺 Stream EntrepreneurTV for Free 📺

More Than 100,000 WordPress Websites Reportedly Infected by Russian Malware Google has already flagged 11,000 malicious domains -- though it is likely that many more than that have been compromised by a mysterious virus called 'SoakSoak.'

By Geoff Weiss

entrepreneur daily

Opinions expressed by Entrepreneur contributors are their own.

Updated on July 17 at 1:55 p.m. with comments from a WordPress spokesperson.

Over 100,000 WordPress sites have been infected by a Russian virus called SoakSoak, which loads an attack code onto webpages created through the uber-popular blogging platform, according to a report by Ars Technica.

Google has already flagged roughly 11,000 malicious domains -- though it is likely that many more than that have been compromised.

According to Gizmodo, more than 70 million total sites use WordPress as a content-management system -- from personal blogs to Time.com. However, only self-hosted sites that use WordPress have been affected by the malware -- meaning personal blogs are okay.

The aim of the hackers and the consequences of the virus -- whether to steal data or otherwise -- remain unclear.

Related: 5 Lessons Leaders Can Learn From the Sony Hacking Scandal

The malware infiltrated WordPress through a vulnerability in a slideshow plug-in called Slider Revolution. While Slider Revolution has since fixed the bug with updates -- it knew about the vulnerability earlier this fall, according to Gizmodo -- the older version of the plug-in is still bundled with many WordPress themes.

"The biggest issue is that the RevSlider plugin is a premium plugin," wrote Sucuri, an online security firm that was first to identify the infection. "It's not something everyone can easily upgrade and that in itself becomes a disaster for website owners."

Ars Technica notes that Sucuri also offers a free scanner here, which can determine which sites are actively compromised.

A WordPress spokesperson could neither confirm that 100,000 sites had been infected, nor that 70 million sites use the platform as a CMS.

"Automattic [WordPress.com's parent company] is taking action to protect sites from the vulnerability," the company said in a statement. "VaultPress, a backup and security product, has included protection from this vulnerability since it was first announced back in September."

Related: Get This: Sony Hack Reveals Company Stored Passwords in Folder Labeled 'Password'

Geoff Weiss

Former Staff Writer

Geoff Weiss is a former staff writer at Entrepreneur.com.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Business News

McDonald's Is Responding to Sky-High Fast Food Prices By Rolling Out a Much Cheaper Value Meal: Report

The news comes as the chain looks to redirect back to customer "affordability."

Starting a Business

Clinton Sparks Podcast: CEO of Complex Shares How Media, Culture Have Shifted in Recent Years

This podcast is a fun, entertaining and informative show that will teach you how to succeed and achieve your goals with practical advice and actionable steps given through compelling stories and conversations with Clinton and his guests.

Fundraising

My Startup Couldn't Raise VC Funding, So We Became Profitable. Here's How We Did It — And How You Can Too.

Four months ago, my startup reached profitability for the first time. It came after more than a year of active work and planning, and here's what it took.

Starting a Business

Clinton Sparks Podcast: From Hit Records to Humanitarian Powerhouse, Akon Shares His Entrepreneurial Journey

This podcast is a fun, entertaining and informative show that will teach you how to succeed and achieve your goals with practical advice and actionable steps given through compelling stories and conversations with Clinton and his guests.

Business Ideas

63 Small Business Ideas to Start in 2024

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2024.