Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.

  1. WordPress Vulnerability & Patch Roundup November 2022

    Research Sucuri, 29 Nov 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  2. Patching an Arbitrary Plugin Disablement Bug in the “webmaster-tools-verification” Plugin

    Research Patchstack, 29 Nov 2022

    Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repos...

  3. New Wave of SocGholish cid=27x Injections

    Research Sucuri, 23 Nov 2022

    On November 15th, Ben Martin reported a new type of WordPress infection resulting in the injection of SocGholish scripts into web pages. The attack loads zipped malicious templates from WordPress theme and fake plugins files before extra...

  4. WP-CLI: How to Install WordPress via SSH

    Research Sucuri, 22 Nov 2022

    Sure, there are tons of one-click installers floating around for WordPress. But they’re not always the most secure option - and can still be tedious to use, especially if you need to update default configurations after installation. But ...

  5. How to Fix the “This Site May Harm Your Computer” Warning

    Research Sucuri, 17 Nov 2022

    Most modern web browsers and search authorities like Google have a vested interest in protecting their users from malware. Warning messages like “ This site may harm your computer ” are a clear way for services to educate and protect end...

  6. New SocGholish Malware Variant Uses Zip Compression & Evasive Techniques

    Research Sucuri, 15 Nov 2022

    Readers of this blog should already be familiar with SocGholish: a widespread, years-long malware campaign aimed at pushing fake browser updates to unsuspecting web users. Once installed, fake browser updates infect the victim’s computer...

  7. Patching Remote Code Execution in the ‘member-hero’ Plugin

    Research Patchstack, 15 Nov 2022

    Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repos...

  8. Massive ois[.]is Black Hat Redirect Malware Campaign

    Research Sucuri, 9 Nov 2022

    Since September 2022, our research team has tracked a surge in WordPress malware redirecting website visitors to fake Q&A sites via ois[.]is . These malicious redirects appear to be designed to increase the authority of the attacker’s si...

  9. Patching an Arbitrary File Download Vulnerability in wsm-downloader

    Research Patchstack, 8 Nov 2022

    Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open source projects. With an initial focus on plugins found in the WordPress.org plugin repos...

  10. Black Friday & Cyber Monday Ecommerce Security Threats

    Research Sucuri, 1 Nov 2022

    Consumers spent a whopping $33.9 billion during Cyber Week last year. With the average adult spending $430 on Black Friday alone, this period remains one of the biggest online shopping events of the year. Unfortunately, hackers are makin...

  11. Patchstack Weekly #46: How To Protect WordPress Against Cross-Site Scripting Attacks (XSS)

    Research Patchstack, 31 Oct 2022

    Welcome to the Patchstack Weekly Security Update, Episode 46! This update is for week 44 of 2022. This week I was surprised to find I have not yet talked about the most prevalent security bug found in web applications in these weekly epi...

  12. WordPress Vulnerability & Patch Roundup October 2022

    Research Sucuri, 28 Oct 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  13. Malware vs Virus: What’s the Difference?

    Research Sucuri, 25 Oct 2022

    There appears to be a general misunderstanding among internet users about the difference between malware and viruses. The two terms are often used interchangeably - and to an extent, this is perfectly fine. But in today’s article, we’ll ...

  14. Patchstack Weekly #45: What Is an Open Redirect Bug (and Why It’s Dangerous)?

    Research Patchstack, 24 Oct 2022

    Welcome to the Patchstack Weekly Security Update, Episode 45! This update is for week 43 of 2022. Last week’s news included a new WordPress security release. WordPress 6.0.3 was made publicly available on Monday October 17th. You can rea...

  15. Patchstack Alliance September Winners & Leaderboard

    Research Patchstack, 21 Oct 2022

    With another busy month behind us, let’s see what the Patchstack Alliance members dug up in September! Our researchers found 53 confirmed vulnerabilities. 9 of the vulnerabilities were found in plugins with 100,000+ installs across WordP...

  16. Wordfence Evasion Malware Conceals Backdoors

    Research Sucuri, 20 Oct 2022

    Malware authors, with some notable exceptions, tend to design their malicious code to hide from sight. The techniques they use help their malware stay on the victim’s website for as long as possible and ensure execution. For example - ob...

  17. WordPress 6.0.3 Security Release Summary

    Research Patchstack, 17 Oct 2022

    Summary A new WordPress security release was announced today. On October 17th, 2022 WordPress Core released version 6.0.3 a security only release. This release includes a substantial number of security bug patches, so I will be reviewing...

  18. How to (Securely) Debug WordPress Errors on Your Website

    Research Sucuri, 13 Oct 2022

    While working on or maintaining your WordPress website, you’ll inevitably encounter an error that prevents it from properly functioning. Knowing how to securely debug and troubleshoot WordPress is an exceptionally important skill. But th...

  19. SiteCheck Malware Trends Report - Q3 2022

    Research Sucuri, 12 Oct 2022

    For the latest malicious scripts, check out our SiteCheck 2023 Mid-Year Malware Trends report. Our free SiteCheck remote website scanner provides immediate insights about malware infections, blocklisting, website anomalies, and errors fo...

  20. What is a Malware Attack?

    Research Sucuri, 6 Oct 2022

    A malware attack is the act of injecting malicious software to infiltrate and execute unauthorized commands within a victim’s system without their knowledge or authorization. The objectives of such an attack can vary - from stealing clie...

  21. Patchstack Helps One.com Fix 56,000 WordPress Vulnerabilities for Their Customers

    Research Patchstack, 5 Oct 2022

    We’ve always said the best way to handle website security is by preventing attacks in the first place. We’re happy to announce that One.com is the latest hosting provider joining the spearhead to tackle open-source security problems at t...

  22. WordPress Vulnerability & Patch Roundup September 2022

    Research Sucuri, 29 Sep 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  23. New Malware Variants Serve Bogus CloudFlare DDoS Captcha

    Research Sucuri, 27 Sep 2022

    When attackers shift up their campaigns, change their payload or exfiltration domains, and put some extra effort into hiding their malware it’s usually a telltale sign that they are making some money off of their exploits. One such campa...

  24. Patchstack Alliance August Winners & Leaderboard

    Research Patchstack, 16 Sep 2022

    It’s September, which means it’s time to look back at what our security researchers got up to in the last month of summer - and what a hot time it was! A very busy august The Patchstack Alliance reported 105 new validated vulnerabilities...

  25. What Is Clickjacking & How Do I Prevent It?

    Research Sucuri, 8 Sep 2022

    Originally published: September 8, 2022 by Antony Garand There are a plethora of techniques that attackers use to redirect site visitors and harvest sensitive information on compromised websites. But when most webmasters think about secu...

  26. How to Find & Remove Malware in Favicon (.ico) Files

    Research Sucuri, 6 Sep 2022

    When a website is hacked symptoms can sometimes include unexpected, unfamiliar and strangely located favicon or .ico files. Other symptoms might include: ”This site may be hacked” warnings Strange redirects to spam websites Blocklisting ...

  27. Patchstack Weekly #39: WordPress 6.0.2 Security Release Details

    Research Patchstack, 5 Sep 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 36 of 2022. This week, I will be giving an unofficial WordPress Security Release announcement discussing the changes I found in the recent 6.0.2 release. And ...

  28. Patchstack Is Partnering With Hostinger to Make WordPress Safer

    Research Patchstack, 2 Sep 2022

    We’re excited to announce a partnership between Patchstack and Hostinger! With the help of Patchstack, Hostinger is now providing all its customers with up-to-date information about security vulnerabilities in their WordPress websites. I...

  29. What is HTTP Error 500 & How to Fix It

    Research Sucuri, 1 Sep 2022

    A frustrating interruption to anyone’s day is the infamous HTTP Error 500 internal server error message . When it happens not only do you lose traffic or potential site revenue, but it can also reflect badly on your site’s reputation and...

  30. WordPress Vulnerabilities & Patch Roundup - August 2022

    Research Sucuri, 30 Aug 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  31. Patchstack Weekly #38: What is Your Time to Patch?

    Research Patchstack, 29 Aug 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 35 of 2022. This week’s vulnerability roundup will feature three plugins that did not receive patches for serious bugs found in their code recently and one pl...

  32. How to Remove 404 Errors in Search Console

    Research Sucuri, 25 Aug 2022

    Hacked websites are known to result in a plethora of headaches for webmasters, including malicious redirects, broken links, and unwanted spam content. But did you also know that it can also result in problems for web crawlers like Google...

  33. Examining Less-Common WordPress Credit Card Skimmers

    Research Sucuri, 23 Aug 2022

    Since 2020 considerable attention has been spent analysing the emergence of MageCart malware within WordPress environments which most commonly affects sites using WooCommerce. As demonstrated in a previous post WordPress has quickly beco...

  34. Patchstack Weekly #37: What Is a CVSS Score?

    Research Patchstack, 22 Aug 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 34 of 2022. This week, I will share with you two plugins that patched security bugs you should know about in the weekly vulnerability roundup. But first, the ...

  35. Fake DDoS Pages On WordPress Sites Lead to Malicious Downloads

    Research Sucuri, 18 Aug 2022

    It’s not uncommon for users to experience “DDoS Protection” pages when casually browsing the web. These DDoS protection pages are typically associated with browser checks performed by WAF/CDN services which verify if the site visitor is,...

  36. SocGholish Malware: Script Injections, Domain Shadowing, IPs & Obfuscation Techniques

    Research Sucuri, 16 Aug 2022

    In June 2022, we shared information about the ongoing NDSW/NDSX malware campaign which has been one of the most common website infections detected and cleaned by our remediation team in the last few years. This NDSW/NDSX malware - also r...

  37. Patchstack Alliance July Winners & Leaderboard

    Research Patchstack, 15 Aug 2022

    Each month we give out rewards and recognition to our community of security researchers and ethical hackers for their contributions to finding WordPress vulnerabilities. Below you’ll find the leaderboard and winners of July’s bug hunt. J...

  38. Patchstack Weekly #36: What Makes a Good Security Bug Patching Practice?

    Research Patchstack, 15 Aug 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 33 of 2022. In this week’s knowledge share where I will be discussing the practice of handling security bugs. I will then discuss only one insecure plugin in ...

  39. 7 Tips to Clean & Maintain Your Website

    Research Sucuri, 2 Aug 2022

    Most people would agree - living in a house full of accumulated debris and unnecessary objects can create a chaotic environment, and even cause health problems. This scenario is easily applicable to your website, too. You can think of yo...

  40. Patchstack Weekly #34: Why You Shouldn’t Use Nulled Plugins and Themes

    Research Patchstack, 1 Aug 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 31 of 2022. In this week’s knowledge share, I will talk about nulled plugins and themes - how they are a hidden security risk, how they harm trust in open sou...

  41. WordPress Vulnerabilities & Patch Roundup - July 2022

    Research Sucuri, 29 Jul 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  42. Cryptominers & WebAssembly in Website Malware

    Research Sucuri, 21 Jul 2022

    WebAssembly (also referred to as Wasm) is a binary instruction format that runs in the browser to enable high-performance applications on web pages and can be executed much faster than traditional JavaScript. WebAssembly can be executed ...

  43. PrestaShop Skimmer Concealed in One Page Checkout Module

    Research Sucuri, 19 Jul 2022

    PrestaShop is a popular freemium open source e-commerce platform used by hundreds of thousands of webmasters to sell products and services to website visitors. While PrestaShop’s CMS market share is only 0.8%, it should still come as no ...

  44. Patchstack Weekly #32: Are Millions of WordPress Sites Really Under Attack?

    Research Patchstack, 18 Jul 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 29 of 2022. This week’s weekly knowledge share is a response to the all too common headlines about “Millions of WordPress websites are under attack” we see ev...

  45. Patchstack Alliance - June Winners and Leaderboard

    Research Patchstack, 15 Jul 2022

    Welcome one and all to the monthly Patchstack Alliance round-up! Each month we give out rewards and recognition to our community of researchers for their contributions to finding WordPress vulnerabilities. Below you’ll find the leaderboa...

  46. How to Avoid Abandoned WordPress Plugins and Themes

    Research Patchstack, 15 Jul 2022

    Abandonware is a silent security risk. With no developer or project lead to address bugs, especially security bugs, you are running code that has no support. If, or when, a security bug is found in an unsupported or abandoned project, th...

  47. Security Lessons Learned from 2021

    Research Sucuri, 14 Jul 2022

    There’s no one specific topic or target or audience when it comes to website security. But when you clean enough hacked websites, you start to see trends and techniques emerge in the landscape. In my last presentation at WordCamp Europe,...

  48. Infected WordPress Site Reveals Malicious C&C Script

    Research Sucuri, 12 Jul 2022

    Bitcoin prices are down 60% year to date, trading far from the all-time highs of $69,000 seen last November. Some altcoins have plummeted even farther in value, with digital currencies collapsing in value in the past six months. While we...

  49. Patchstack Weekly #31: Why You Should Remove Unused Plugins

    Research Patchstack, 11 Jul 2022

    This week I will talk about the importance of removing unused code and components from your websites. Simply disabling a theme or plugin is not enough - reviewing and deleting these things has to become a habit. I will also cover a few v...

  50. SiteCheck Malware Trends Report - Q2 2022

    Research Sucuri, 7 Jul 2022

    For the latest malicious scripts, check out our SiteCheck 2023 Mid-Year Malware Trends report. Conducting an external website scan for indicators of compromise is one of the easiest ways to identify security issues. While remote scanners...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support