WordPress site redirecting visitors? Check the mu-plugins folder
In March 2026 we cleaned up a backdoor campaign that hit several WordPress sites in the same week. Each one showed the same pattern: visitors were being sent to fake browser update pages, the Plugins screen looked normal, and the malicious code sat in a folder most site owners have never opened. That folder is wp-content/mu-plugins, and security researchers have