Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 2 min ago.

  1. Ninja Forms plugin flaw exploited to hack WordPress sites

    News BleepingComputer, 6 Oct 2026

    Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

  2. WordPress 7.1.3 Security Release

    Research Patchstack, 6 Oct 2026

    WordPress 7.1.3 landed on 6 October 2026. It’s a maintenance and security release with seven security fixes and four bug fixes. Two weeks ago, 7.1.2 fixed a single vulnerability (CVE-2026-87902) that allowed an unauthenticated visitor to...

  3. Four ways back in: the WordPress XSS campaign that hides its own admin account

    Research Patchstack, 6 Oct 2026

    Two unrelated WordPress plugins, two separate stored Cross-Site Scripting vulnerabilities, one payload. Over the past several days our telemetry has recorded exploitation attempts against both, and every attempt pulls the same JavaScript...

  4. Wordfence Intelligence Weekly WordPress Vulnerability Report (September 21, 2026 to September 27, 2026)

    Research Wordfence, 1 Oct 2026

    Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your...

  5. WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

    News The Hacker News, 1 Oct 2026

    Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has...

  6. SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor

    Research Sucuri, 1 Oct 2026

    Overview During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’l...

  7. [webapps] WordPress 7.0.2 - Path Travesal

    Exploit Exploit-DB, 1 Oct 2026

    WordPress 7.0.2 - Path Travesal

  8. Quarterly WordPress Threat Intelligence Report - Q2 2026

    Research Wordfence, 29 Sep 2026

    Wordfence's Q2 2026 threat intelligence report covers 2,073 published WordPress vulnerabilities, 182 high threat vulnerabilities, 10.4 billion blocked WAF attacks, 18.2 billion blocked brute force attacks, and 573K infected sites, plus t...

  9. Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

    News The Hacker News, 26 Sep 2026

    Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cros...

  10. Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites

    Research Patchstack, 25 Sep 2026

    This blog post is about a Cross-Site Request Forgery vulnerability in the Elementor Website Builder plugin. One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perfo...

  11. Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)

    Research Wordfence, 24 Sep 2026

    Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulnerability Researchers that contributed ...

  12. WordPress Remote Code Execution Vulnerability

    Advisory HKCERT (Hong Kong), 24 Sep 2026

  13. PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core

    Research Wordfence, 22 Sep 2026

    WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should upd...

  14. CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch

    Research Patchstack, 22 Sep 2026

    Yesterday we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up on what we are seeing h...

  15. Inside a Malicious, Stealthy WordPress Must Use Plugin

    Research Wordfence, 22 Sep 2026

    The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. TThe malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal

  16. WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE

    Research Patchstack, 22 Sep 2026

    WordPress 7.1.2 landed on 22 September 2026. It’s a security-only release with a single fix, and that fix is the most serious thing WordPress has patched in a while: an unauthenticated local file inclusion in page template resolution tha...

  17. WordPress Multiple Vulnerabilities

    Advisory HKCERT (Hong Kong), 22 Sep 2026

  18. Click2Shell: The RCE WordPress 7.1.1 Just Patched

    Research Patchstack, 18 Sep 2026

    WordPress 7.1.1 patched a vulnerability reported by pwn.ai’s Paulos Yibelo named Click2Shell, a complicated vulnerability chaining Cross-Site Request Forgery (CSRF) into selector injection to turn a single click into a remote shell. It w...

  19. Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server

    Research Wordfence, 18 Sep 2026

    Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target...

  20. Patchstack Now Protects Your AI-Built Apps

    Research Patchstack, 18 Sep 2026

    WordPress isn’t the only place people build websites anymore. AI builders and Node.js hosting are now standard offerings from our own hosting partners, and that shift has quietly recreated every security problem we spent five years solvi...

  21. WordPress 7.1.1 Maintenance and Security Release

    Research Patchstack, 18 Sep 2026

    WordPress 7.1.1 landed on 17 September 2026. It’s a security and maintenance release with 11 security fixes and 17 Core bug fixes. The headline issue is an unauthenticated stored cross-site scripting (XSS) vulnerability in wpautop(), the...

  22. 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

    Research Wordfence, 17 Sep 2026

    Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible.

  23. Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)

    Research Wordfence, 17 Sep 2026

    Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your...

  24. Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

    Research Wordfence, 14 Sep 2026

    On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerabil...

  25. WordPress Security Plugins: How to Choose the Right One

    Research Sucuri, 5 Sep 2026

    In short , WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a fire...

  26. Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

    Research Patchstack, 28 Aug 2026

    This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one activ...

  27. Case study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack

    Research Patchstack, 24 Aug 2026

    Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse. Updates can’t close that gap alone, especially when...

  28. One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

    Research Patchstack, 21 Aug 2026

    Reported by the DigitalOcean security team, with root cause analysis by DigitalOcean, coverage and vendor follow-up handled jointly with Patchstack. Most vulnerability write-ups are about the bug. This is primarily about everything aroun...

  29. What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk

    Research Sucuri, 19 Aug 2026

    Each feature that you add to a website results in a new element that has to be managed. The credentials are accepted by a login page, the data by a contact form, new code is introduced by a plugin, and an API is used to connect your webs...

  30. Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin

    Research Patchstack, 19 Aug 2026

    This blog post is about an unauthenticated arbitrary file upload vulnerability in the Elementor Pro plugin that leads to remote code execution. The flaw lives in the Forms module’s File Upload field, where the extension check and the fil...

  31. FlyWP Adds Proactive Vulnerability Protection with Patchstack

    Research Patchstack, 17 Aug 2026

    We’re excited to announce that FlyWP has integrated Patchstack into their platform, bringing proactive WordPress vulnerability protection to their customers through a new security add-on: FlySecurity Pro. FlyWP offers managed WordPress c...

  32. [webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

    Exploit Exploit-DB, 17 Aug 2026

    WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

  33. The Illusion of a Lock - How AI is changing the speed and scale of hands-on WordPress vulnerability research.

    Research Sucuri, 15 Aug 2026

    2026: the year the tools learned to hack In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, t...

  34. When a PNG Isn’t a PNG: WordPress Patches an Author-Level Imagick RCE

    Research Patchstack, 12 Aug 2026

    The latest WordPress maintenance release 7.0.4 includes a quiet but important security fix, and it’s one worth understanding rather than just clicking “update” past. It changes how WordPress hands your uploaded media to ImageMagick, and ...

  35. How to Create a Secure WordPress Staging Site: Beginner’s Guide

    Research Sucuri, 11 Aug 2026

    Updating WordPress directly on a live website can cause avoidable problems. A plugin update might break checkout, or a theme change could create layout issues visitors see immediately. A WordPress staging site gives you a separate place ...

  36. WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

    Research Patchstack, 6 Aug 2026

    WordPress 7.0.3 landed on 6 August 2026. It’s a security release with 12 different fixes covering pre-auth cross-site scripting (XSS), stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass,...

  37. Vulnerability & Patch Roundup - July 2026

    Research Sucuri, 31 Jul 2026

    Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already...

  38. Protect The Shire solves one problem, but risks making another worse

    Research Patchstack, 30 Jul 2026

    We looked at the data: what WordPress.org’s 24-hour update delay means for vulnerabilities and supply-chain attacks. WordPress.org’s new update-review policy - Protect the Shire - is doing exactly what it was built to do - for one kind o...

  39. Ninety minutes: watching attackers weaponize the WordPress core RCE

    Research Patchstack, 22 Jul 2026

    When we published our advisory on July 17, we ended it with the usual line: update immediately. We meant it, but we also knew what tends to happen next. A critical, unauthenticated, pre-auth chain in WordPress core is exactly the kind of...

  40. Unauthenticated SQL Injection in WordPress Core Fixed in 7.0.2

    Research Patchstack, 17 Jul 2026

    Update: Patchstack has independently verified that these combined vulnerabilities can lead to full site takeovers, including remote code execution. We advise all users to update immediately and review your WordPress site for any users yo...

  41. Why Delaying WordPress Updates Increases Security Risks

    Research Sucuri, 14 Jul 2026

    WordPress updates help close known vulnerabilities before automated attacks can find and exploit them. Once a patch is released, attackers often move quickly to scan for sites that have not yet updated. It’s easy to put off updates when ...

  42. Vulnerability & Patch Roundup - June 2026

    Research Sucuri, 2 Jul 2026

    Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already...

  43. WordPress PBN Plugin Drops Dual Webshells via Database Injection

    Research Sucuri, 16 Jun 2026

    During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web s...

  44. Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins

    Research Patchstack, 15 Jun 2026

    Published June 15, 2026, by the Patchstack Team A supply chain attack against three popular WordPress marketing plugins (OptinMonster, TrustPulse, and PushEngage) served tampered JavaScript from their vendors’ CDNs to live websites. The ...

  45. WordPress Site Down? Here’s How to Get Back Online

    Research Sucuri, 22 May 2026

    If your WordPress site goes offline, every minute costs you lost sales, missed leads, and a dent in visitor trust. Search engines may start flagging errors, and customers see a blank page instead of your business. In that moment, the pre...

  46. WPScan 4.0.0: We’re Back

    Research WPScan, 20 May 2026

    WPScan 4.0.0 is here. We read through years of community issues. We addressed every major complaint. 75+ open issues → 0. Explicit scan control. Authentication‑based enumeration. Real‑time streaming. Consolidated codebase. This is WPScan...

  47. Vulnerability & Patch Roundup - April 2026

    Research Sucuri, 1 May 2026

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  48. WordPress DDoS Protection: How to Keep Your Site Online

    Research Sucuri, 23 Apr 2026

    WordPress powers over 40% of the web, which makes it one of the most attractive targets for Distributed Denial of Service (DDoS) attacks. If your site goes down for an hour, you lose revenue, search rankings, and visitor trust. If it goe...

  49. HostArmada Adds Patchstack to Its Security Stack

    Research Patchstack, 21 Apr 2026

    We’re excited to announce that HostArmada has integrated Patchstack into their platform - bringing proactive WordPress vulnerability protection to their customers through a new security add-on called Armada V-Shield. HostArmada is a fast...

  50. Supply Chain Compromise: Trojanized Copy of WowShipping Pro Installs Hidden Remote Access Toolkit

    Research Patchstack, 17 Apr 2026

    This blog post is a technical analysis of a trojanized copy of WowShipping Pro version 1.0.6 for WordPress, a commercial plugin sold by WPXPO. Patchstack received a copy of the plugin from a site owner who traced a client site compromise...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support