• This plugin previously worked well and the support was good.

    However, in May 2026, my site was affected by a serious security issue involving this plugin. A hidden backdoor plugin was installed.

    This plugin was capable of:

    • Letting an attacker log in as any user, including admins.
    • Hiding a suspicious user account called sectest.
    • Changing MyCryptoCheckout wallet addresses.
    • Redirecting customer crypto payments to attacker-controlled wallets.

    Based on my experience, I would strongly advise other users to carefully check their WordPress admin users, unauthorised activity in the admin panel, hidden plugin files, and MyCryptoCheckout wallet addresses.

    My previous review was flagged and removed.

    • This topic was modified 2 days, 14 hours ago by john doe.
Viewing 1 replies (of 1 total)
  • Plugin Contributor js2484

    (@uniquelylost)

    Hi,

    We published a full postmortem and remediation guidance for the May MyCryptoCheckout security incident.

    The incident involved unauthorized access to part of the MCC API server environment connected to the Linux “Copy Fail” / CVE-2026-31431 vulnerability. Copy Fail/Dirty Frag was a high‑severity security vulnerability in the Linux kernel that affected major Linux distributions released since 2017. Microsoft and major security firms have documented how this exact vulnerability exposed millions of Linux workloads globally during that same window.

    https://www.techzine.eu/news/security/140968/linux-distributions-worldwide-targeted-by-the-copy-fail-exploit/

    During the affected window, unauthorized update_account messages were sent to a subset of MCC installations.

    Since then, we have rebuilt API infrastructure, restricted API access for older plugin versions, and released numerous hardened plugin updates with stricter handling/sanitization of remote account data before local storage.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this review.