HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 3 min ago.
- Critical Vulnerability Discovered in WooCommerce Payments
Research Sucuri, 24 Mar 2023
On March 22nd, 2023 a critical vulnerability was discovered within the WooCommerce Payments plugin - an extremely popular eCommerce payment plugin for WordPress with over half a million active installations. Thankfully the vulnerability ...
- User Registration Plugin Vulnerability
Research Patchstack, 24 Mar 2023
This blog post is about the User Registration plugin vulnerability. If you’re a User Registration user, please update the plugin to at least version 2.3.3. User Registration WordPress plugin The plugin User Registration (versions 2.3.2.1...
- Critical Vulnerability in WooCommerce Payments
Research Patchstack, 23 Mar 2023
This security advisory is written about the critical vulnerability in WooCommerce Payments, which is a privilege escalation vulnerability. Patchstack users have received a vPatch to protect their site against this vulnerability. Update M...
- WooCommerce Credit Card Skimmer Reveals Tampered Plugin
Research Sucuri, 21 Mar 2023
Disclaimer: The malware infection described in this article does not affect the software plugin as a whole and does not indicate any vulnerabilities or security flaws within WooCommerce or any associated WooCommerce plugin extensions. Ov...
- The Complete Guide To WordPress Security
Research Patchstack, 17 Mar 2023
The thought of your WordPress site being hacked is terrifying. A single attack can cause system downtime, data loss, and reputational damage - it’s a nightmare scenario. But it doesn’t have to be. At Patchstack, we’ve seen firsthand the ...
- What is a Headless CMS?
Research Sucuri, 16 Mar 2023
Running a website isn’t easy, but modern content management systems (CMS) like WordPress have revolutionized the way you can manage your website. Headless CMS solutions take this a step further, decoupling the back-end source of the webs...
- How to Find & Fix the WordPress Pharma Hack
Research Sucuri, 14 Mar 2023
Finding bogus content and unexpected links for prescription drugs on your WordPress website can be a frustrating experience. But don’t blame your site: it just got caught up in a bad crowd of black hat SEO spammers and fell victim to a p...
- Patchstack Weekly #62: The Patchstack State of WordPress Security Report
Research Patchstack, 14 Mar 2023
Welcome to the Patchstack Weekly Security Update, Episode 62! This update is for week 11 of 2023. In this week’s knowledge share, I will be sharing a review of Patchstack’s annual ‘State of WordPress Security’ report. This report was jus...
- Patching a Stored XSS Bug In the “tinymce-custom-styles” Plugin
Research Patchstack, 6 Mar 2023
Welcome back to Patchstack’s “Last Patch”. This is a special episode, normally these blog posts are lessons in defensive coding tactics using a plugin that has already been disabled due to abandonment. However, in this post I will share ...
- Magbo Spam Injection Encoded with hex2bin
Research Sucuri, 3 Mar 2023
We recently had a new client come to us with a rather peculiar issue on their WordPress website: They were receiving unwanted popup advertisements but only when the website was accessed through links posted on FaceBook . Initially we tho...
- Security Vulnerability In OceanWP Theme <= 3.4.1
Research Patchstack, 1 Mar 2023
There is a vulnerability in the OceanWP theme - Subscriber+ Path Traversal Leading to Local File Inclusion in <= 3.4.1 If you’re an OceanWP user, please update the theme to at least version 3.4.2. About the OceanWP Theme The theme OceanW...
- Patchstack Weekly #61: Should you use WordPress As a Headless CMS?
Research Patchstack, 28 Feb 2023
Welcome to the Patchstack Weekly Security Update, Episode 61. This is update is for week 9 of 2023. In last week’s knowledge share, I talked about static sites, I mentioned headless CMS being different and a topic for another week. Well,...
- WordPress Vulnerability & Patch Roundup February 2023
Research Sucuri, 27 Feb 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Vulnerability In Houzez Theme Exploited in The Wild
Research Patchstack, 27 Feb 2023
There is a security vulnerability in Houzez Theme that is exploited in the wild. The vulnerability in Houzez Theme is an Unauthenticated Privilege Escalation vulnerability. The Houzez theme is a premium theme sold on ThemeForest and has ...
- Is My Site Hacked? (13 Signs)
Research Sucuri, 23 Feb 2023
Symptoms of a hack can vary wildly. A concerning security alert from Google, a browser warning when you visit your site, or even a notice from your hosting provider that they’ve taken down your website - all of these events may indicate ...
- Attackers Abuse Cron Jobs to Reinfect Websites
Research Sucuri, 21 Feb 2023
Malicious cron jobs are nothing new; we’ve seen attackers use them quite frequently to reinfect websites. However, in recent months we’ve noticed a distinctive new wave of these infections that appears to be closely related to this artic...
- Multiple Vulnerabilities In Shortcodes Ultimate Plugin Versions <=5.12.6
Research Patchstack, 21 Feb 2023
If you’re a Shortcodes Ultimate user, please update the plugin to at least version 5.12.7. Introduction The plugin Shortcodes Ultimate (versions 5.12.6 and below), which has over 700,000 active installations is known as a plugin that pro...
- Patchstack Weekly #60: Should You Convert WordPress To a Static Site?
Research Patchstack, 20 Feb 2023
Welcome to the Patchstack Weekly Security Update, Episode 60! This update is for week 8 of 2023. This week’s news is about static sites and security. Did you know with the right plugin WordPress can be used to generate HTML? If you have ...
- The Dangers of Installing Nulled WordPress Themes & Plugins
Research Sucuri, 16 Feb 2023
Nulled WordPress themes and plugins are a controversial topic for many in the web development world - and arguably one of the bigger threats to WordPress security. Essentially modified versions of official WordPress themes and plugins wi...
- Help! My Email Server Got B0rked & I Have Problems After Malware Infection!
Research Sucuri, 14 Feb 2023
The Sucuri Firewall functions as a reverse proxy. A simple change to your DNS settings is all it takes to thoroughly filter incoming traffic to sniff and parse out bad requests from the good ones. However, these DNS changes can affect co...
- Vulnerability In Rank Math SEO Plugin
Research Patchstack, 14 Feb 2023
There’s a vulnerability in Rank Math SEO Plugin. If you’re a Rank Math SEO user, please update the plugin to at least version 1.0.107.3. Introduction The plugin Rank Math SEO (versions 1.0.107.2 and below), which has over 1,000,000 activ...
- Bogus URL Shorteners Redirect Thousands of Hacked Sites in AdSense Fraud Campaign
Research Sucuri, 9 Feb 2023
Late last year we reported on a malware campaign targeting thousands of WordPress websites to redirect visitors to bogus Q&A websites. The sites themselves contained very little useful information to a regular visitor, but - more importa...
- Konami Code Backdoor Concealed in Image
Research Sucuri, 2 Feb 2023
Attackers are always looking for new ways to conceal their malware and evade detection, whether it’s through new forms of obfuscation, concatenation, or - in this case - unorthodox use of image file extensions. One of the most common bac...
- Multiple Vulnerabilities Fixed In WP Statistics Plugin Version <= 13.2.10
Research Patchstack, 2 Feb 2023
If you’re a WP Statistics plugin user, please update the plugin to at least version 13.2.11. Introduction The plugin WP Statistics (versions 13.2.10 and below), which has over 600.000 active installations is a Privacy-focused analytics p...
- Solving Unpredictable WP-Cron Problems, Addressing CVE-2023-22622
Research Patchstack, 1 Feb 2023
Introduction This article will introduce concepts about how computers schedule tasks with cron and how WordPress’s cron implementation “WP-Cron” works more like a queue instead of a scheduler. I will share some of the implications queuei...
- WordPress Vulnerability & Patch Roundup January 2023
Research Sucuri, 30 Jan 2023
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- WPMU DEV’s Defender Pro Now Powered by Patchstack’s Vulnerability Feed
Research Patchstack, 25 Jan 2023
These are interesting times for open-source security. Over the past year or so we’ve seen a significant increase in collaboration when it comes to making the WordPress ecosystem safer. This is a strong signal that the community is moving...
- Massive Campaign Uses Hacked WordPress Sites as Platform for Black Hat Ad Network
Research Sucuri, 24 Jan 2023
Every so often attackers register a new domain to host their malware. In many cases, these new domains are associated with specific malware campaigns, often related to redirecting legitimate website traffic to third party sites of their ...
- Multiple Critical Vulnerabilities Fixed In LearnPress Plugin Version <= 4.1.7.3.2
Research Patchstack, 24 Jan 2023
If you’re a LearnPress user, please update the plugin to at least version 4.2.0. Introduction to the LearnPress plugin vulnerability The plugin LearnPress (versions 4.1.7.3.2 and below), which has over 100,000 active installations is a c...
- Patchstack Weekly #56: How Can Developers Prove Their Plugins Are Secure?
Research Patchstack, 23 Jan 2023
Welcome to the Patchstack Weekly Security Update, Episode 56! This update is for week 4 of 2023. This week’s knowledge share is for developers and site owners alike. I will be discussing how open source projects (really any code project)...
- Vulnerable WordPress Sites Compromised with Different Database Infections
Research Sucuri, 19 Jan 2023
Vulnerabilities within WordPress can lead to compromise, and oftentimes known vulnerabilities are utilized to infect WordPress sites with more than one infection. It is common for out of date websites to be attacked by multiple threat ac...
- Is WordPress Secure?
Research Sucuri, 17 Jan 2023
According to W3Techs, 43.2% of all websites on the internet use WordPress. And of all websites that use a CMS (Content Management System) more than half (64%) leverage WordPress to power their blog or website. Unfortunately, since WordPr...
- Multiple MainWP Vulnerabilities Affecting Its Extensions
Research Patchstack, 17 Jan 2023
Introduction to MainWP vulnerabilities At Patchstack we accept vulnerability reports from individual researchers but also do our own research - often by randomly selecting a plugin. This time it happens that, during a quick inspection of...
- Patchstack Weekly #55: How To Choose a Secure Web Hosting Provider?
Research Patchstack, 16 Jan 2023
In the dynamic world of web hosting, the foundation of your WordPress website’s security lies in the choice of your hosting provider. When it comes to your WordPress site, security isn’t merely an option - it’s an absolute necessity. A s...
- How to Fix “There Has Been a Critical Error on This Website”
Research Sucuri, 12 Jan 2023
Critical errors on any system can be extremely frustrating. But if you’ve recently encountered the “ There has been a critical error on this website ” message on your WordPress site, don’t fret! In many cases, critical errors are the res...
- Patchstack Weekly #54: How To Make Sure Your Sites Are Running Safe WordPress Plugins
Research Patchstack, 10 Jan 2023
Welcome to the Patchstack Weekly Security Update, Episode 54! This update is for week 2 of 2023. This week’s knowledge share will continue the trend of new years resolutions. I am honored to share with you these simple tasks you can do, ...
- How To Find & Remove Malware on Weebly Sites
Research Sucuri, 5 Jan 2023
Weebly is an easy-to-use website builder that allows admins to quickly create and publish responsive blogs and sites. Website builder environments are usually considered to be very safe and not prone to malware infections, but during a r...
- WordPress Vulnerability & Patch Roundup December 2022
Research Sucuri, 28 Dec 2022
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...
- Patching an XSS Security Bug in “add-comments” Plugin
Research Patchstack, 22 Dec 2022
Accepting your mistakes. The human experience is full of mistakes, failures, and folly. I would say this is “the truth” but this statement itself may be wrong, and I accept that .. but I’m saying this first to make my next point. Mistake...
- How to Backup a WordPress Site for Free with WP-CLI
Research Sucuri, 22 Dec 2022
Regular website backups are the foundation of a solid website security plan. In the event of data loss or malware infection, restoring a WordPress backup helps you quickly and easily recover your environment and revert it back to its las...
- Fake jQuery Domain Redirects Site Visitors to Scam Pages
Research Sucuri, 20 Dec 2022
A recent infection has been making its rounds across vulnerable WordPress sites, detected on over 160 websites so far at the time of writing. The infection is injected at the top of legitimate JavaScript files and executes a script from ...
- Backdoor Targets FreePBX Asterisk Management Portal
Research Sucuri, 15 Dec 2022
Written in PHP and JavaScript, FreePBX is a web-based open-source GUI that manages Asterisk, a voice over IP and telephony server. This open-source software allows users to build customer phone systems. During a recent investigation, I c...
- Most Common WordPress Vulnerabilities & How to Fix Them
Research Patchstack, 13 Dec 2022
The purpose of this article is to provide information to developers and researchers regarding how vulnerabilities can exist in their plugins or themes and how these vulnerabilities can get patched up in order to increase the safety of th...
- Patching an Arbitrary User Creation Security Bug in “thecartpress” Plugin
Research Patchstack, 12 Dec 2022
When people come together, contribute to a like-minded goal. Great things can happen. Community is inherent in any successful open source project. The good news is, connecting with others is something humans are good at doing. The bad ne...
- How to Securely Shop With Your Credit Card: Use a Virtual Card & Check for Skimmers
Research Sucuri, 8 Dec 2022
The convenience and ease of online transactions has drawn a tremendous number of users to online ecommerce storefronts. And during the pandemic, many consumers switched to online purchases in favor of shopping at regular brick and mortar...
- Patching a Broken Access Control Bug in the “account-manager-woocommerce” Plugin
Research Patchstack, 7 Dec 2022
The great open-source bazaar. This is the idea to bring as many vendors (open source developers) under one roof (or repository) to share their wares with whoever may be interested. This sounds well and good, but this bazaar has one big s...
- How to Fix & Remove the “Click Allow If You Are Not a Robot” Redirect
Research Sucuri, 6 Dec 2022
Attackers are always finding unique ways to avoid detection. Our teams regularly find malware on compromised websites which have been obfuscated to make it more difficult for webmasters to detect or understand. Obfuscation can take many ...
- December WordPress Bug-Hunting Challenge
Research Patchstack, 5 Dec 2022
We are beyond excited to celebrate the winter holidays and the launch of the Patchstack Alliance Discord community with a special WordPress bug-hunting event taking place throughout December 2022. In December, we released a public leader...
- Patchstack Weekly #50: When Hacks Come Back
Research Patchstack, 5 Dec 2022
Welcome to the Patchstack Weekly Security Update, Episode 50! This update is for week 49 of 2022. This week’s knowledge share is about the lingering problems that can happen after a compromise. This is related to the recent news of LastP...
- Chinese Gambling Spam Targets World Cup Keywords
Research Sucuri, 2 Dec 2022
Since 2018, our team has been tracking an interesting type of website infection where the tag of a hacked website is changed to Chinese text - changes which are clearly seen in the website’s search results and source code. However, when ...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.