Buy, Wait, Weaponise: The Essential Plugin WordPress Supply Chain Attack
An attacker bought 30+ WordPress plugins on Flippa for six figures, planted a dormant backdoor, waited eight months, then activated it to serve SEO spam to Googlebot across hundreds of thousands of sites.