WordPress sites hacked through defunct Rich Reviews plugin
An estimated 16,000 websites are believed to be running a vulnerable and no-longer-maintained WordPress plugin that can be exploited to display pop-up ads and redirect visitors to webpages containing porn, scams, and–worst of all–malware designed to infect users’ computers.
Read more in my article on the Tripwire State of Security blog.