HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 2 min ago.
- Ninja Forms plugin flaw exploited to hack WordPress sites
News BleepingComputer, 6 Oct 2026
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
- WordPress 7.1.3 Security Release
Research Patchstack, 6 Oct 2026
WordPress 7.1.3 landed on 6 October 2026. It’s a maintenance and security release with seven security fixes and four bug fixes. Two weeks ago, 7.1.2 fixed a single vulnerability (CVE-2026-87902) that allowed an unauthenticated visitor to...
- Four ways back in: the WordPress XSS campaign that hides its own admin account
Research Patchstack, 6 Oct 2026
Two unrelated WordPress plugins, two separate stored Cross-Site Scripting vulnerabilities, one payload. Over the past several days our telemetry has recorded exploitation attempts against both, and every attempt pulls the same JavaScript...
- Wordfence Intelligence Weekly WordPress Vulnerability Report (September 21, 2026 to September 27, 2026)
Research Wordfence, 1 Oct 2026
Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your...
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
News The Hacker News, 1 Oct 2026
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has...
- SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor
Research Sucuri, 1 Oct 2026
Overview During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’l...
- [webapps] WordPress 7.0.2 - Path Travesal
Exploit Exploit-DB, 1 Oct 2026
WordPress 7.0.2 - Path Travesal
- Quarterly WordPress Threat Intelligence Report - Q2 2026
Research Wordfence, 29 Sep 2026
Wordfence's Q2 2026 threat intelligence report covers 2,073 published WordPress vulnerabilities, 182 high threat vulnerabilities, 10.4 billion blocked WAF attacks, 18.2 billion blocked brute force attacks, and 573K infected sites, plus t...
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
News The Hacker News, 26 Sep 2026
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cros...
- Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites
Research Patchstack, 25 Sep 2026
This blog post is about a Cross-Site Request Forgery vulnerability in the Elementor Website Builder plugin. One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perfo...
- Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)
Research Wordfence, 24 Sep 2026
Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed ...
- WordPress Remote Code Execution Vulnerability
Advisory HKCERT (Hong Kong), 24 Sep 2026
- PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
Research Wordfence, 22 Sep 2026
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should upd...
- CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
Research Patchstack, 22 Sep 2026
Yesterday we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up on what we are seeing h...
- Inside a Malicious, Stealthy WordPress Must Use Plugin
Research Wordfence, 22 Sep 2026
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. TThe malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal
- WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE
Research Patchstack, 22 Sep 2026
WordPress 7.1.2 landed on 22 September 2026. It’s a security-only release with a single fix, and that fix is the most serious thing WordPress has patched in a while: an unauthenticated local file inclusion in page template resolution tha...
- WordPress Multiple Vulnerabilities
Advisory HKCERT (Hong Kong), 22 Sep 2026
- Click2Shell: The RCE WordPress 7.1.1 Just Patched
Research Patchstack, 18 Sep 2026
WordPress 7.1.1 patched a vulnerability reported by pwn.ai’s Paulos Yibelo named Click2Shell, a complicated vulnerability chaining Cross-Site Request Forgery (CSRF) into selector injection to turn a single click into a remote shell. It w...
- Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Research Wordfence, 18 Sep 2026
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target...
- Patchstack Now Protects Your AI-Built Apps
Research Patchstack, 18 Sep 2026
WordPress isn’t the only place people build websites anymore. AI builders and Node.js hosting are now standard offerings from our own hosting partners, and that shift has quietly recreated every security problem we spent five years solvi...
- WordPress 7.1.1 Maintenance and Security Release
Research Patchstack, 18 Sep 2026
WordPress 7.1.1 landed on 17 September 2026. It’s a security and maintenance release with 11 security fixes and 17 Core bug fixes. The headline issue is an unauthenticated stored cross-site scripting (XSS) vulnerability in wpautop(), the...
- 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Research Wordfence, 17 Sep 2026
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.
- Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
Research Wordfence, 17 Sep 2026
Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your...
- Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
Research Wordfence, 14 Sep 2026
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerabil...
- WordPress Security Plugins: How to Choose the Right One
Research Sucuri, 5 Sep 2026
In short , WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a fire...
- Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP
Research Patchstack, 28 Aug 2026
This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one activ...
- Case study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack
Research Patchstack, 24 Aug 2026
Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse. Updates can’t close that gap alone, especially when...
- One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
Research Patchstack, 21 Aug 2026
Reported by the DigitalOcean security team, with root cause analysis by DigitalOcean, coverage and vendor follow-up handled jointly with Patchstack. Most vulnerability write-ups are about the bug. This is primarily about everything aroun...
- What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
Research Sucuri, 19 Aug 2026
Each feature that you add to a website results in a new element that has to be managed. The credentials are accepted by a login page, the data by a contact form, new code is introduced by a plugin, and an API is used to connect your webs...
- Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin
Research Patchstack, 19 Aug 2026
This blog post is about an unauthenticated arbitrary file upload vulnerability in the Elementor Pro plugin that leads to remote code execution. The flaw lives in the Forms module’s File Upload field, where the extension check and the fil...
- FlyWP Adds Proactive Vulnerability Protection with Patchstack
Research Patchstack, 17 Aug 2026
We’re excited to announce that FlyWP has integrated Patchstack into their platform, bringing proactive WordPress vulnerability protection to their customers through a new security add-on: FlySecurity Pro. FlyWP offers managed WordPress c...
- [webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Exploit Exploit-DB, 17 Aug 2026
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
- The Illusion of a Lock - How AI is changing the speed and scale of hands-on WordPress vulnerability research.
Research Sucuri, 15 Aug 2026
2026: the year the tools learned to hack In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, t...
- When a PNG Isn’t a PNG: WordPress Patches an Author-Level Imagick RCE
Research Patchstack, 12 Aug 2026
The latest WordPress maintenance release 7.0.4 includes a quiet but important security fix, and it’s one worth understanding rather than just clicking “update” past. It changes how WordPress hands your uploaded media to ImageMagick, and ...
- How to Create a Secure WordPress Staging Site: Beginner’s Guide
Research Sucuri, 11 Aug 2026
Updating WordPress directly on a live website can cause avoidable problems. A plugin update might break checkout, or a theme change could create layout issues visitors see immediately. A WordPress staging site gives you a separate place ...
- WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed
Research Patchstack, 6 Aug 2026
WordPress 7.0.3 landed on 6 August 2026. It’s a security release with 12 different fixes covering pre-auth cross-site scripting (XSS), stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass,...
- Vulnerability & Patch Roundup - July 2026
Research Sucuri, 31 Jul 2026
Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already...
- Protect The Shire solves one problem, but risks making another worse
Research Patchstack, 30 Jul 2026
We looked at the data: what WordPress.org’s 24-hour update delay means for vulnerabilities and supply-chain attacks. WordPress.org’s new update-review policy - Protect the Shire - is doing exactly what it was built to do - for one kind o...
- Ninety minutes: watching attackers weaponize the WordPress core RCE
Research Patchstack, 22 Jul 2026
When we published our advisory on July 17, we ended it with the usual line: update immediately. We meant it, but we also knew what tends to happen next. A critical, unauthenticated, pre-auth chain in WordPress core is exactly the kind of...
- Unauthenticated SQL Injection in WordPress Core Fixed in 7.0.2
Research Patchstack, 17 Jul 2026
Update: Patchstack has independently verified that these combined vulnerabilities can lead to full site takeovers, including remote code execution. We advise all users to update immediately and review your WordPress site for any users yo...
- Why Delaying WordPress Updates Increases Security Risks
Research Sucuri, 14 Jul 2026
WordPress updates help close known vulnerabilities before automated attacks can find and exploit them. Once a patch is released, attackers often move quickly to scan for sites that have not yet updated. It’s easy to put off updates when ...
- Vulnerability & Patch Roundup - June 2026
Research Sucuri, 2 Jul 2026
Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already...
- WordPress PBN Plugin Drops Dual Webshells via Database Injection
Research Sucuri, 16 Jun 2026
During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web s...
- Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins
Research Patchstack, 15 Jun 2026
Published June 15, 2026, by the Patchstack Team A supply chain attack against three popular WordPress marketing plugins (OptinMonster, TrustPulse, and PushEngage) served tampered JavaScript from their vendors’ CDNs to live websites. The ...
- WordPress Site Down? Here’s How to Get Back Online
Research Sucuri, 22 May 2026
If your WordPress site goes offline, every minute costs you lost sales, missed leads, and a dent in visitor trust. Search engines may start flagging errors, and customers see a blank page instead of your business. In that moment, the pre...
- WPScan 4.0.0: We’re Back
Research WPScan, 20 May 2026
WPScan 4.0.0 is here. We read through years of community issues. We addressed every major complaint. 75+ open issues → 0. Explicit scan control. Authentication‑based enumeration. Real‑time streaming. Consolidated codebase. This is WPScan...
- Vulnerability & Patch Roundup - April 2026
Research Sucuri, 1 May 2026
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- WordPress DDoS Protection: How to Keep Your Site Online
Research Sucuri, 23 Apr 2026
WordPress powers over 40% of the web, which makes it one of the most attractive targets for Distributed Denial of Service (DDoS) attacks. If your site goes down for an hour, you lose revenue, search rankings, and visitor trust. If it goe...
- HostArmada Adds Patchstack to Its Security Stack
Research Patchstack, 21 Apr 2026
We’re excited to announce that HostArmada has integrated Patchstack into their platform - bringing proactive WordPress vulnerability protection to their customers through a new security add-on called Armada V-Shield. HostArmada is a fast...
- Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit
Research Patchstack, 17 Apr 2026
This blog post is a technical analysis of a trojanized copy of WowShipping Pro version 1.0.6 for WordPress, a commercial plugin sold by WPXPO. Patchstack received a copy of the plugin from a site owner who traced a client site compromise...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.