via pluginvulnerabilities.com => original post link
For a couple of months now, a phishing email campaign has been sending emails warning of a vulnerability on WordPress websites and telling people to download a plugin for that. That email has this format:
Dear user [Read more]