Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 4 min ago.

  1. Attackers Abuse Poorly Regulated Top-Level Domains in Ongoing Redirect Campaign

    Research Sucuri, 18 Feb 2022

    One of the more common infections that we see are site-wide redirects to spam and scam sites, achieved by attackers exploiting newly found vulnerabilities in popular WordPress plugins. If you’ve ever been redirected to a page that looks ...

  2. Patchstack Partners Up With Plesk

    Research Patchstack, 17 Feb 2022

    We’re beyond excited to announce that Plesk has selected Patchstack as its security partner to allow WP Toolkit users to detect security vulnerabilities in their WordPress websites. Patchstack will be integrated with WP Toolkit to provid...

  3. How do I secure WordPress Websites for Free?

    Research Sucuri, 15 Feb 2022

    Protecting Content Management Systems (CMS) installed on a hosting server is crucial in today’s ever-growing world wide web, but how to I protect my WordPress website on a tight budget? There are tons of options available on this front, ...

  4. Patchstack Weekly, Week 06: Preparing for SQL Injection

    Research Patchstack, 14 Feb 2022

    Welcome back to the Patchstack Weekly security update! This update is for week 6 of 2022. Last week, two high severity vulnerabilities were patched by the developers of WP Spell Check and Revolut Gateway for WooCommerce. Both of these pl...

  5. How to Choose a Security Plugin That’s Right for Your Website

    Research Sucuri, 11 Feb 2022

    Finding the perfect security plugin for your website is important, but it’s also crucial you find the proper one that suits your needs. WordPress plugins are a dime a dozen, so we’ll be discussing how to narrow your options and what to l...

  6. Top 10 Security Tips to Keep Your WordPress Site Healthy

    Research Sucuri, 9 Feb 2022

    As we go through the winter months and whether changes, many of us go to our local pharmacy and take advantage of a flu shot. We do this because maybe we have had the flu before and the second of pain from the jab is nothing in compariso...

  7. Critical Vulnerability Fixed In Responsive Menu Plugin

    Research Patchstack, 8 Feb 2022

    The plugin Responsive Menu - Create Mobile-Friendly Menu (versions 4.1.7 and below), which has over 100.000 active installations, suffers from a critical vulnerability. This vulnerability allows any authenticated user, regardless of thei...

  8. Are all Websites Hackable? Why (not)?

    Research Sucuri, 4 Feb 2022

    Frankly, no security is 100% secure. As infections continue to surge across the web, and attackers think of more innovative ways to remain undetected, many site owners wonder if they’ll be the next victim. In this article we’ll discuss w...

  9. WooCommerce Skimmer Uses Fake Fonts and Favicon to Steal CC Details

    Research Sucuri, 2 Feb 2022

    The holidays are always a busy time for ecommerce stores. Dealing with an influx of Christmas shoppers, holiday sales and inventory, shipping, and at times, also hackers. Today’s investigation starts out much like many others, with our c...

  10. What Happens When a Vulnerability in WordPress Plugin Is Found?

    Research Patchstack, 1 Feb 2022

    This blog post introduces the many players in open-source security and what happens when we find a vulnerability in WordPress plugin. There are people in many different roles, that play a part in open-source security beyond the developer...

  11. Top Ways Websites get Hacked by Spammers

    Research Sucuri, 31 Jan 2022

    There’s a lot that goes into a website environment in terms of functionality. Due to this, it’s only natural for one of the most commonly asked questions being how websites are usually hacked. In my previous post I talk about the Most In...

  12. Why are WordPress Websites Targeted by Hackers?

    Research Sucuri, 27 Jan 2022

    If you are wondering why your wordpress site keeps getting hacked, or why you’re being targeted by hackers, we’ve compiled some of the top reasons for you. WordPress is one of the most commonly used Content Management Systems across the ...

  13. Critical Vulnerability Fixed In Essential Addons for Elementor Plugin

    Research Patchstack, 27 Jan 2022

    A critical vulnerability was fixed in the WordPress plugin Essential Addons for Elementor. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin developers, we have security audit servic...

  14. Un-Patched Insecure WordPress Themes Update

    Research Patchstack, 24 Jan 2022

    An Update A few weeks ago we disclosed the first batch of insecure WordPress themes with an un-patched authenticated vulnerability within them. This post is a follow up, where we disclose more issues in those same themes. You can read ou...

  15. Everything You Need to Know About Web Application Firewalls

    Research Sucuri, 24 Jan 2022

    WAFs (Web Application Firewalls) are nothing new as they used to primarily be deployed by large organizations. In today’s modern web however, they’re becoming increasingly common for the average site owner to deploy. So what is a web app...

  16. Patchstack Weekly by Robert

    Research Patchstack, 21 Jan 2022

    Patchstack weekly is a weekly security update made by Patchstack Security Advocate Robert Rowley. Every week Robert highlights the mentionable WordPress vulnerabilities, helps us learn something new about security, and gives thanks and a...

  17. AccessPress Themes Hit With Targeted Supply Chain Attack

    Research Sucuri, 20 Jan 2022

    Security researchers at Automattic recently reported that the popular WordPress plugin and theme authors AccessPress were compromised and their software replaced with backdoored versions. The compromise appears to have taken place in Sep...

  18. Patchstack Weekly, Week 03: WordPress Vulnerabilities & Cross-Site Request Forgery

    Research Patchstack, 20 Jan 2022

    Welcome back to the Patchstack Weekly security update. It is the third week of 2022 and this episode is called WordPress vulnerabilities & Cross-Site Request Forgery. Within this session, I will inform you of 6 popular open-source WordPr...

  19. What Should You do if Your WordPress Site was Hacked?

    Research Sucuri, 19 Jan 2022

    These days WordPress infections are very common. In 2021, internetlivestats.com counted over 81 million websites hacked. If you’re one of the millions, you need to take action to fix and protect your site. Of course, a hacked site will p...

  20. Understanding Website SQL Injections

    Research Sucuri, 18 Jan 2022

    SQL injection is one of the most common types of web hacking techniques used today. As data breaches continue to happen to some of the most high-profile corporations and brands, it’s become more important for web users to adapt to these ...

  21. Patchstack Weekly, Week 02: Unpatched Vulnerabilities & Supporting Open Source

    Research Patchstack, 13 Jan 2022

    Welcome back to the Patchstack Weekly security update! This is Episode 6, released in the 2nd week of 2022. This episode focuses on two main topics - disclosure of unpatched vulnerabilities and supporting open source. In this week’s sess...

  22. The People Behind Us - Website Security Champions 2021

    Research Sucuri, 12 Jan 2022

    Kayleigh Martin is a tier 2 Website Security Analyst. Her daily responsibilities include investigating sites for malware, removing the malware, and advising clients on how to prevent future attacks. The most exciting part of her day is f...

  23. Authenticated Vulnerability in Unpatched WordPress Themes

    Research Patchstack, 11 Jan 2022

    The decision to publicly report a vulnerability that has no patch does not come easily, however, in certain circumstances it is the only option available to protect users from running insecure code. You may have guessed where I am going ...

  24. Patchstack App Tutorial: Writing Custom Firewall Rules

    Research Patchstack, 11 Jan 2022

    This blog post explains how to write custom firewall rules using Patchstack app. Patchstack App users get automatic protection against new plugin vulnerabilities via the default WAF (web application firewall) rules which are enough for m...

  25. WordPress 5.8.3 Security Release

    Research Sucuri, 8 Jan 2022

    On January 6th, an important security update was released for the WordPress core addresses four separate vulnerabilities. WordPress website administrators are advised to update their websites immediately. All WordPress versions between 3...

  26. Technical Advisory: WordPress Core 5.8.3 Security Update

    Research Patchstack, 7 Jan 2022

    On the 6th of January 2022, WordPress.org released a security update and recommended users to “update your sites immediately”. This WordPress core 5.8.3 security update addresses 4 different security vulnerabilities which affect WordPres...

  27. A Walk Through a Year of Website Security: Part II

    Research Sucuri, 5 Jan 2022

    Part I of our 2021 Security Walkthrough shows the initial 5 posts of our top 10. 6 - Vulnerable Plugin Exploited in Spam Redirect Campaign It was brought to our malware research team’s attention that a vulnerability was discovered in old...

  28. Is WordPress Secure? 5 Biggest Do’s And Don’ts In WordPress Security

    Research Patchstack, 1 Jan 2022

    In this article, we won’t dive into technical details, but try to address a common misconception instead. We will explain what website security is in general, how to secure WordPress and answer the question - is WordPress secure? As per ...

  29. Patchstack Weekly, Week 52: Critical Plugin Vulnerability & Backlog of Unpatched Components

    Research Patchstack, 30 Dec 2021

    Welcome back to the Patchstack Weekly security update! This update is for week 52 of 2021. This week marks the final week of 2021, and with the year coming to a close it is a great time to reflect on the past, present, and future. So tha...

  30. How do I Know if a Website is Safe to Use my Credit Card?

    Research Sucuri, 29 Dec 2021

    With regular news stories about companies being hacked, database breaches, internet-breaking vulnerabilities and online credit card theft, web users are justifiably anxious about making online purchases for fear that their personal infor...

  31. Most Interesting Vulnerabilities of 2021

    Research Sucuri, 27 Dec 2021

    As with most years, there’s been a wide array of critical vulnerabilities found within content management systems, plugins, API keys, etc. We’ll be recapping our discoveries and how these vulnerabilities were exploited, or potentially co...

  32. How to Add SSL & Move WordPress from HTTP to HTTPS

    Research Sucuri, 23 Dec 2021

    Making sure your website uses HTTPS should be a top priority for any webmaster In fact, recent statistics show that over 42% of site administrators across the web use WordPress, and many of these sites still don’t have an SSL certificate...

  33. Patchstack Weekly, Week 51: WordPress Vulnerabilities And Code Stewardship

    Research Patchstack, 23 Dec 2021

    Welcome back to the Patchstack Weekly security update! This update is for week 51 of 2021. See the 49th Patchstack Weekly and the 50th Patchstack Weekly here. This week’s news may sound like deja-vu, as I will cover more of the same topi...

  34. New Improved WordPress Login Page Protection

    Research Patchstack, 22 Dec 2021

    With the latest version of the Patchstack plugin, we have re-introduced WordPress login page protection - a feature to block access to the standard login page. About security through obscurity Recently we removed the ability to “hide” th...

  35. Critical Vulnerabilities in All in One SEO Plugin Affects Millions of WordPress Websites

    Research Sucuri, 21 Dec 2021

    Security Risk: High Exploitation Level: Easy CVSS Score: 9.9 / 7.7 Vulnerability: Privilege Escalation, SQL Injection Patched Version: 4.1.5.3 Last week, security researcher at Automattic Marc Montpas recently discovered two severe secur...

  36. Patchstack Alliance (Red Team) Interview With Lenon Leite

    Research Patchstack, 21 Dec 2021

    In this article, we will introduce our Alliance (formerly Red Team) member Lenon Leite. Lenon has been an Alliance member since March 2021. Patchstack Alliance is a community of independent security researchers who contribute to building...

  37. How to Find and Fix a WordPress Pharma Hack

    Research Sucuri, 16 Dec 2021

    Did you know that one quarter of all spam emails are accredited to pharmaceutical ads? Pharma hacks go beyond the inbox and spam websites by redirecting traffic and adding fake keywords and subdomains to the search results. Why, and how ...

  38. Patchstack Weekly, Week 50: WordPress Vulnerabilities And Log4j

    Research Patchstack, 16 Dec 2021

    Welcome to the Patchstack Weekly Security Update! This update is for week 50 of 2021. It is mid-December, and we are still waiting to see the total impact of a vulnerability reported in the open-source component: log4j. This is a library...

  39. If You Approach WordPress Security Like This, It’s Easy

    Research Patchstack, 16 Dec 2021

    With nearly a decade of working on WordPress security and website security, we’ve probably seen every kind of attack you could imagine. Some breaches are obvious while many might go undetected for months or even longer. This makes it har...

  40. How Malware Gets On Your Website

    Research Sucuri, 13 Dec 2021

    Almost since the Internet’s inception malware infections have kept pace to be the biggest nuisance a site owner experiences. With an ever growing amount of sites making up the World Wide Web, malware infections only become more common. I...

  41. Patchstack Weekly, Week 49: Gravatar Breach and Web History

    Research Patchstack, 9 Dec 2021

    Welcome back to the Patchstack Weekly security update, this update is for December 9th, 2021. We will talk about the Gravatar breach, web history, and vulnerabilities from this week. In this week’s session, we have two high-risk vulnerab...

  42. PHP Re-Infectors: How To Stop PHP Malware That Keeps Coming Back

    Research Sucuri, 8 Dec 2021

    We all know why bad actors infect sites: monetary gain, boosts in SEO ratings for their malware or spam campaigns and a number of other reasons explained in our post on hacker’s motivations. It defeats the purpose of the attack if the ma...

  43. WooCommerce Credit Card Swiper Injected Into Random Plugin Files

    Research Sucuri, 6 Dec 2021

    It’s that time of year again! While website owners always need to be on guard, the holidays season is when online scams and credit card theft are most rampant. Administrators of ecommerce websites need to be extra vigilant as this case w...

  44. Is My Site Hacked? 4 Gut Checks

    Research Sucuri, 3 Dec 2021

    The consequences of a hacked site have wide-ranging financial repercussions that extend beyond the cost of cleaning the site. Drop-offs can be anticipated for new sales from prospects spooked by “not secure” url warning labels. The same ...

  45. Patchstack Weekly, Week 48: Dependency Confusion

    Research Patchstack, 2 Dec 2021

    Welcome back to the Patchstack Weekly Security update! This update is for December 2nd, 2021 and in this update, I will focus on dependency confusion. This week is a good week, there are no high-risk vulnerabilities to report on in the W...

  46. An In-Depth Analysis Of The WP-VCD Malware

    Research Patchstack, 2 Dec 2021

    The WP-VCD malware for WordPress has existed for many years. It mainly spreads by injecting itself into legitimate plugins and themes after which it will spread itself on sites that offer downloads to (nulled) WordPress plugins and theme...

  47. WordPress Admin Creator - A Simple, But Effective Attack

    Research Sucuri, 1 Dec 2021

    Malicious admin users get added to vulnerable WordPress sites often. This can happen in a variety of different ways, and sometimes the malware that creates these malicious users can hide in plain sight. Injecting a malicious admin user i...

  48. Patchstack Weekly, Week 47: Incident Response & Vulnerability News

    Research Patchstack, 25 Nov 2021

    Welcome to the Patchstack Weekly. It’s week 47 and this week we talk about incident response, Hide My WP vulnerabilities, and GoDaddy breach. This update is for November 25th, 2021. This week’s news is about a breach at a major hosting p...

  49. Why You Shouldn’t Use SMS For 2FA

    Research Sucuri, 24 Nov 2021

    Two factor authentication (2FA) provides an extra layer of security that passwords alone can’t provide. Requiring an extra step for users to verify their identity reduces the chance a bad actor can gain access to data however. One of the...

  50. Multiple Security Vulnerabilities Fixed In Hide My WP by wpWave

    Research Patchstack, 24 Nov 2021

    There were multiple security vulnerabilities fixed in the Hide My WP plugin by wpWave which allowed unauthenticated SQL injection and allowed unauthenticated users to retrieve a token to deactivate the plugin. Do you want to be the first...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support