To mitigate these attacks, WordPress has taken several proactive steps:
Forced Password Reset: WordPress initiated a mandatory password reset for all plugin authors and other users identified by security researchers as having credentials exposed in data breaches. This move aims to ensure that compromised passwords are no longer in use.
Encouraging Two-Factor Authentication: Plugin authors are strongly encouraged to adopt two-factor authentication to enhance account security.
Temporary Block on Plugin Updates: WordPress temporarily halted all new plugin updates unless they received explicit approval from the WordPress team. This precautionary measure was intended to prevent plugins from being updated with malicious backdoors. By Monday, WordPress confirmed that plugin releases were no longer paused.