8 Popular WordPress Plugins Are Currently Being Exploited By Hackers – Search Engine Journal
Duplicator (1 million+ installs)
Duplicator is a plugin that lets site owners export the content of their sites. A bug was patched in version 1.3.28 that allowed attackers to export site contents, including database credentials.
ThemeGrill Demo Importer (200,000 installs)
A bug in this plugin, which comes with themes sold by ThemeGrill, allowed attackers to wipe sites and take over the admin account. This bug was patched in version 1.6.3.
Profile Builder Plugin (65,000 installs)
A bug in the free and paid versions of this plugin allowed hackers to register unauthorized admin accounts. This bug was patched on February 10th.