Title: this plugin was compromised
Last modified: June 7, 2026

---

# this plugin was compromised

 *  [john doe](https://wordpress.org/support/users/iniquus/)
 * (@iniquus)
 * [11 hours, 46 minutes ago](https://wordpress.org/support/topic/this-plugin-was-compromised/)
 * This plugin previously worked well and the support was good.
 * **However, in May 2026, my site was affected by a serious security issue involving
   this plugin. A hidden backdoor plugin was installed.**
   This plugin was capable
   of:
    - Letting an attacker log in as any user, including admins.
    - Hiding a suspicious user account called `sectest`.
    - Changing MyCryptoCheckout wallet addresses.
    - Redirecting customer crypto payments to attacker-controlled wallets.
 * Based on my experience, I would strongly advise other users to carefully check
   their WordPress admin users, unauthorised activity in the admin panel, hidden
   plugin files, and MyCryptoCheckout wallet addresses.
   My previous review was flagged
   and removed.
    -  This topic was modified 11 hours, 42 minutes ago by [john doe](https://wordpress.org/support/users/iniquus/).

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fthis-plugin-was-compromised%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this review.

 * ![](https://ps.w.org/mycryptocheckout/assets/icon.svg?rev=1869074)
 * [MyCryptoCheckout - Bitcoin, Ethereum, and 100+ altcoins for WooCommerce](https://wordpress.org/plugins/mycryptocheckout/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/mycryptocheckout/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/mycryptocheckout/)
 * [Active Topics](https://wordpress.org/support/plugin/mycryptocheckout/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/mycryptocheckout/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/mycryptocheckout/reviews/)

 * 0 replies
 * 1 participant
 * Last reply from: [john doe](https://wordpress.org/support/users/iniquus/)
 * Last activity: [11 hours, 46 minutes ago](https://wordpress.org/support/topic/this-plugin-was-compromised/)