Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,885 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.

  1. Patchstack Weekly #32: Are Millions of WordPress Sites Really Under Attack?

    Research Patchstack, 18 Jul 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 29 of 2022. This week’s weekly knowledge share is a response to the all too common headlines about “Millions of WordPress websites are under attack” we see ev...

  2. Patchstack Alliance - June Winners and Leaderboard

    Research Patchstack, 15 Jul 2022

    Welcome one and all to the monthly Patchstack Alliance round-up! Each month we give out rewards and recognition to our community of researchers for their contributions to finding WordPress vulnerabilities. Below you’ll find the leaderboa...

  3. How to Avoid Abandoned WordPress Plugins and Themes

    Research Patchstack, 15 Jul 2022

    Abandonware is a silent security risk. With no developer or project lead to address bugs, especially security bugs, you are running code that has no support. If, or when, a security bug is found in an unsupported or abandoned project, th...

  4. Security Lessons Learned from 2021

    Research Sucuri, 14 Jul 2022

    There’s no one specific topic or target or audience when it comes to website security. But when you clean enough hacked websites, you start to see trends and techniques emerge in the landscape. In my last presentation at WordCamp Europe,...

  5. Infected WordPress Site Reveals Malicious C&C Script

    Research Sucuri, 12 Jul 2022

    Bitcoin prices are down 60% year to date, trading far from the all-time highs of $69,000 seen last November. Some altcoins have plummeted even farther in value, with digital currencies collapsing in value in the past six months. While we...

  6. Patchstack Weekly #31: Why You Should Remove Unused Plugins

    Research Patchstack, 11 Jul 2022

    This week I will talk about the importance of removing unused code and components from your websites. Simply disabling a theme or plugin is not enough - reviewing and deleting these things has to become a habit. I will also cover a few v...

  7. SiteCheck Malware Trends Report - Q2 2022

    Research Sucuri, 7 Jul 2022

    For the latest malicious scripts, check out our SiteCheck 2023 Mid-Year Malware Trends report. Conducting an external website scan for indicators of compromise is one of the easiest ways to identify security issues. While remote scanners...

  8. Top 5 Most Common WordPress Malware Infections: An Anatomy Lesson

    Research Sucuri, 5 Jul 2022

    WordPress security is serious business - and an essential consideration for anyone using the world’s most popular CMS (Content Management System). While the WordPress team quickly addresses known security issues in WordPress’ core to pro...

  9. What is CSV Injection?

    Research Patchstack, 4 Jul 2022

    In this article, we will explain what CSV injection is and how can CSV files be exploited. We will also shed some light on how to secure against CSV injection vulnerabilities and protect your site even further. We will also highlight a p...

  10. WordPress Vulnerabilities & Patch Roundup - June 2022

    Research Sucuri, 30 Jun 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  11. How to Find & Clean Up the AnonymousFox Hack

    Research Sucuri, 28 Jun 2022

    The AnonymousFox hack targets insecure websites and actively exploits them to spread phishing, spam, and other malware. A major nuisance for website owners, it also happens to be one of the more prevalent types of malware seen on client ...

  12. Patchstack Weekly #28: How To Choose Secure Plugins?

    Research Patchstack, 20 Jun 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 25 of 2022. This week’s knowledge share will include some tips for WordPress site owners on what to look out for when choosing secure plugins. I will also sha...

  13. Ninja Forms Plugin Object Injection Security Bug Gets Patched

    Research Patchstack, 17 Jun 2022

    TL;DR A critical security bug in Ninja Forms (1+ million installations) was patched by the plugin’s developers this week. The security bug posed a high risk, as it could result in unauthenticated object injection. Successful attacks coul...

  14. WooCommerce Credit Card Skimmer Uses Telegram Bot to Exfiltrate Stolen Data

    Research Sucuri, 16 Jun 2022

    Our story starts like many others told on this blog: A new client came to us with reported cases of credit card theft on their eCommerce website. The website owner had received complaints from several customers who reported bogus transac...

  15. Patchstack Weekly #27: How to Update wp_options Securely.

    Research Patchstack, 13 Jun 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 24 of 2022. This week I will cover two high risk unauthenticated vulnerabilities, one could allow attackers to reset an any user’s password (including admin u...

  16. WordPress Vulnerability News, May 2023

    Research Patchstack, 13 Jun 2022

    WordPress vulnerability news is a weekly digest of highlighted WordPress plugin security vulnerabilities or vulnerability discloses that have been published (there are other, less critical vulnerabilities on smaller plugins that unfortun...

  17. Smilodon Credit Card Skimming Malware Shifts to WordPress

    Research Sucuri, 9 Jun 2022

    WordPress’ massive market share has come with an unsurprising side effect: As more and more site admins turn to popular plugins like WooCommerce to turn a profit on their website and set up online stores we’ve seen a significant increase...

  18. Patchstack Weekly, Week 23: What Makes A Good WordPress Community?

    Research Patchstack, 7 Jun 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 23 of 2022. It is the beginning of June, and WordCamp Europe is underway as I write this. WordCamps are the in-person community events for the WordPress commu...

  19. Analysis of the Massive NDSW / NDSX Malware Campaign

    Research Sucuri, 2 Jun 2022

    Recently, Avast’s researchers Pavel Novák and Jan Rubín posted a detailed writeup about the “ Parrot TDS ” campaign involving more than 16,500 infected websites. Such massive infections don’t go unnoticed by Sucuri and we immediately rec...

  20. WordPress Vulnerabilities & Patch Round-up - May 2022

    Research Sucuri, 31 May 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. We’ve compiled...

  21. Top Ten Most Cumbersome Website Infections to Remove in 2021

    Research Sucuri, 26 May 2022

    In today’s post we’re going to be going over the top ten most cumbersome website infections to remove, based on the sheer number of files or database entries that they infected on compromised client sites during 2021. Some website malwar...

  22. What’s New In WordPress 6.0?

    Research Patchstack, 25 May 2022

    This week was the official release of WordPress 6.0. The release was named after Grammy award-winning Latin jazz and Afro-Cuban jazz musician Arturo O’Farrill, who has a website running none other than WordPress! What a great reminder, o...

  23. Analyzing a WooCommerce Credit Card Skimmer

    Research Sucuri, 19 May 2022

    The number of credit card skimmers targeting WooCommerce websites has skyrocketed over the past year, and threat actors have become increasingly creative in the different ways they obfuscate their payloads to avoid traditional detection....

  24. X-Cart Skimmer with DOM-based Obfuscation

    Research Sucuri, 17 May 2022

    Our lead security analyst Liam Smith recently worked on an infected X-Cart website and found two interesting credit card stealers there - one skimmer located server-side, the other client-side. X-Cart’s e-commerce platform is not nearly ...

  25. Massive WordPress JavaScript Injection Campaign Redirects to Ads

    Research Sucuri, 11 May 2022

    Our remediation and research teams regularly find malicious redirects on client sites. These infections automatically redirect site visitors to third-party websites with malicious resources, scam pages, or commercial websites with the in...

  26. Winners Of WordPress Bug Hunt 2021

    Research Patchstack, 11 May 2022

    In March 2021, we started a bug-hunting program where together with partners, we reward developers and ethical hackers who help us make the WordPress ecosystem more secure. Since then, we have received more than 1000 security reports and...

  27. Examining Emerging Malware: Website Backdoors

    Research Sucuri, 10 May 2022

    Next up in our “This didn’t quite make it into the 2021 Threat Report, but is still really cool” series: New and emerging backdoor variants from 2021! Contents: What is a website backdoor? How do backdoors work? What are the new types of...

  28. Patchstack Weekly, Week 19: Secure AJAX Endpoints & WordPress Vulnerabilities

    Research Patchstack, 9 May 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 19 of 2022 and is about secure AJAX endpoints and WordPress vulnerabilities. This week in vulnerability news, I will share two WordPress plugins with security...

  29. Manually Identifying an X-Cart Credit Card Skimmer

    Research Sucuri, 5 May 2022

    During a recent investigation, a new client came to us reporting that their antivirus had detected a suspicious domain loading on their website’s checkout page. We regularly receive reports like these, as this is a telltale indicator of ...

  30. WooCommerce Credit Card Skimmers Concealed In Fake Images

    Research Sucuri, 3 May 2022

    Our research and remediation teams have noticed an increase in WooCommerce credit card skimmers on client sites over the past few years, as detailed in past blog posts. Due to the increased number of plugins and components facilitating o...

  31. Why Hosting Companies Should Send Out WordPress Security Alerts?

    Research Patchstack, 29 Apr 2022

    This article shares some light on how WordPress hosting companies can increase their recurring revenue by sending out WordPress security alerts. The majority of security vulnerabilities in the WordPress ecosystem originate from plugins a...

  32. Hacked Website Threat Report 2021

    Research Sucuri, 29 Apr 2022

    Our 2021 Website Threat Research Report details our findings and analysis of emerging and ongoing trends and threats in the website security landscape. We’ve put together this analysis to help keep website owners informed and aware of th...

  33. WordPress Vulnerabilities & Patch Roundup - April 2022

    Research Sucuri, 26 Apr 2022

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educat...

  34. Patchstack Weekly, Week 17: Egoless Programming And Security Bugs

    Research Patchstack, 25 Apr 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 17 of 2022. This week I have a handful of vulnerabilities to share with you. Including 3 unauthenticated SQL injection security bugs that were patched, and 3 ...

  35. Patchstack Weekly, Week 16: WordPress Vulnerabilities And Secure Code Review

    Research Patchstack, 18 Apr 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 16 of 2022 and is about the power of transparency in open source, and how anyone can utilize this transparency to learn secure code review. This week I will t...

  36. Critical RCE Vulnerability in Elementor WordPress Plugin

    Research Sucuri, 14 Apr 2022

    Security Risk: High Exploitation Level: Easy CVSS Score: 9.9 Vulnerability: Remote code execution (RCE) Patched Version: 3.6.3 On April 12th, an important security update was released for the Elementor plugin patching a critical remote c...

  37. Sucuri WordPress Plugin += Sucuri WAF

    Research Sucuri, 14 Apr 2022

    Sucuri has always been a dedicated supporter of the WordPress community. Our free plugin was one of our first contributions to WordPress security (before bootstrapping our efforts into our WAF/CDN, Backups, and Malware Remediation servic...

  38. Critical Vulnerability Fixed In Elementor Plugin Version 3.6.3

    Research Patchstack, 13 Apr 2022

    A critical vulnerability was fixed in the WordPress plugin Elementor. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit services and Threat Intelli...

  39. Patchstack Weekly, Week 15: WordPress Security History

    Research Patchstack, 11 Apr 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 15 of 2022 and will talk about WordPress security history. This week is a special episode. There were not many critical vulnerabilities to cover this week. So...

  40. The Case for 2FA by Default for WordPress

    Research Sucuri, 8 Apr 2022

    Administrator panel compromises are one of the most common attacks that everyday WordPress website admins face. We work with thousands of clients who have encountered attacks on their websites and I’ve long ago lost count of the number o...

  41. WordPress Overtakes Magento in Credit Card Skimmers

    Research Sucuri, 4 Apr 2022

    One of the most important monitoring tools in our security platform is our Sucuri SiteCheck scanner. It’s a free tool to scan your website for known malicious content and malware injections. The usage of SiteCheck also allows us to monit...

  42. Patchstack Weekly, Week 14: Five Steps To A Secure WordPress From Scratch

    Research Patchstack, 4 Apr 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 14 of 2022 and I will talk about the first 5 steps to a secure WordPress. This week has a lot of vulnerability news to cover, and I will be sharing it as a 3-...

  43. WordPress Popunder Malware Redirects to Scam Sites

    Research Sucuri, 1 Apr 2022

    Over the last year we’ve seen an ongoing malware infection which redirects website visitors to scam sites. So far this year our monitoring has detected over 3,000 websites infected with this injection this year and over 17,000 in total s...

  44. New Wave of AnonymousFox Cron Jobs

    Research Sucuri, 30 Mar 2022

    Recently our Remediation and Research teams have noticed a new wave of malicious cron jobs associated with the notorious AnonymousFox malware. The cron jobs are purpose-built to reinfect the victim websites and make removal of the infect...

  45. Patchstack Weekly, Week 13: A New Set Of WP-CLI Security Commands

    Research Patchstack, 28 Mar 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 13 of 2022. This week, I will talk about two high-risk vulnerabilities in two WordPress plugins with one big difference: One was patched, one was not. In this...

  46. The Mystery Admin User

    Research Sucuri, 25 Mar 2022

    One of our clients recently submitted a malware removal request with a curious problem: A mystery admin user kept getting re-created on their website. Try as they might, nothing they did would get rid of this user; it just kept coming ba...

  47. Patchstack Weekly, Week 12: Secure WordPress File Uploads

    Research Patchstack, 21 Mar 2022

    Welcome back to the Patchstack Weekly Security Update! This update is for week 12 of 2022 and this week we’ll talk about WordPress vulnerabilities and WordPress file uploads. This week in WordPress-related vulnerabilities, I will talk ab...

  48. Can you be Hacked by Visiting a Website?

    Research Sucuri, 16 Mar 2022

    Visiting websites throughout the decades has always had its risks. With the creation of Flashplayer and JavaScript, site visitors could potentially be impacted by malicious viruses, like the notorious YouAreAnIdiot[.]org pop-ups that cau...

  49. Patchstack Red Team Is Now Patchstack Alliance

    Research Patchstack, 15 Mar 2022

    Patchstack Red Team is now Patchstack Alliance. Exactly 1 year ago, Patchstack kicked off a bug hunting community that gathered together ethical hackers who contribute to making the WordPress ecosystem more secure. After an exciting year...

  50. Can SSL or an HTTPS Website Be Hacked?

    Research Sucuri, 14 Mar 2022

    This post was last updated October 11th, 2022. It should be no shock by now that a professional can break through anything. These days, zero-days are a dime a dozen, so it’s important to ensure your site is hardened and protected as much...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support