HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- 7 Audacious Hacks & What We Can Learn From Them …
Research Sucuri, 22 Nov 2021
While stressful and costly to the victim, hacks can also be an opportunity for onlookers to learn how to prevent getting breached. Hacks create an opportunity to think creatively about company and personal security and a challenge to mee...
- What is a Website Backdoor?
Research Sucuri, 18 Nov 2021
What is a Backdoor? A backdoor provides a shortcut for authorized or unauthorized users to gain access to an unauthorized location of a website, software, or system. There are many different ways to categorize backdoors, but they are usu...
- The Difference Between Authentication And Authorization
Research Patchstack, 11 Nov 2021
This blog post is about the difference between authentication and authorization and provides some tips for bug hunters and developers alike to better understand how it is handled in WordPress. The difference between authentication and au...
- Understanding .htaccess Malware
Research Sucuri, 11 Nov 2021
The .htaccess file is notorious for being targeted by attackers. Whether it’s using the file to hide malware, redirect search engines to other sites with blackhat SEO tactics, hide backdoors, inject content, modify php.ini values; the po...
- Critical Security Vulnerability Fixed In WP Reset PRO
Research Patchstack, 10 Nov 2021
There was a critical security vulnerability in the WP Reset PRO plugin which allowed any authenticated user to wipe the database. Do you want to be the first to be alerted about such vulnerabilities? Sign up for Patchstack. For plugin de...
- WooCommerce Skimmer Spoofs Checkout Page
Research Sucuri, 8 Nov 2021
Recently a client of ours was reporting a bogus checkout page appearing on their website. When trying to access their “ my-account ” page an unfamiliar prompt appeared in their browser soliciting credit card billing information: This for...
- Welcome To The First Patchstack Weekly Update
Research Patchstack, 4 Nov 2021
Welcome to the Patchstack Weekly Update! It is November 4th, 2021. This is the first of a weekly series where you can get caught up on recent events relevant to open source security, with an initial focus on WordPress security. This seri...
- Introducing New Patchstack Community & Business Plans
Research Patchstack, 2 Nov 2021
We’ve always wanted security to be accessible for as many people as possible. Earlier this year we opened a free-to-use WordPress vulnerability database that the WordPress community could use to keep up with the latest vulnerabilities. W...
- Network Firewall vs. Web Application Firewall (WAF)
Research Sucuri, 1 Nov 2021
Originally published: November 1, 2021 by Allison Bondi As more of business and daily life has moved online, hackers have found a clear opportunity. The costs of data breaches continue to rise, and attacks are becoming harder to detect a...
- Meet Robert Rowley - Patchstacks’ Security Advocate
Research Patchstack, 13 Oct 2021
Our whole team is incredibly happy to announce that Robert Rowley has joined Patchstack as a Security Advocate. Robert has been working in the security field since 2008, including being the director or head of security at prominent WordP...
- What is Cryptocurrency Mining Malware?
Research Sucuri, 28 Sep 2021
Cryptocurrency mining malware is typically a stealthy malware that farms the resources on a system (computers, smartphones, and other electronic devices connected to the internet) to generate revenue for the cyber criminals controlling i...
- 5 Types of Hackers & Why They Hack
Research Sucuri, 20 Sep 2021
When considering why hackers are attacking websites, you might think that there’s a specific reason they target you as a website owner-your business, your reputation, or your information. The truth is, while it feels personal to the vict...
- Patchstack Red Team: 1067 Vulnerabilities And $7700 In Bounties
Research Patchstack, 20 Sep 2021
UPDATE: As of 2022, Patchstack Red Team is known as Patchstack Alliance This is a Patchstack Red Team report for September 2021. In March 2021, Patchstack announced Patchstack Red Team - a community of independent security researchers wh...
- 3 WordPress Security Issues Fixed In Version 5.8.1
Research Patchstack, 17 Sep 2021
WordPress 5.8.1 is now available and there are 3 WordPress security issues fixed in that version. Altogether this security and maintenance release features 60 bug fixes in addition to 3 security fixes we will be focusing on in this artic...
- Analyzing The Photo Gallery by 10Web SQL Injection Vulnerability
Research Patchstack, 13 Sep 2021
On May 15th, 2020, a SQL injection vulnerability for the Photo Gallery plugin by 10Web (with 300k+ active installations) was published by a researcher at Sun* Cyber Security Research. Not soon after this, we noticed an increase in SQL in...
- Multiple Vulnerabilities In MailerLite Sign Up Forms
Research Patchstack, 13 Sep 2021
The MailerLite Sign Up Forms plugin (version 1.4.4 and below) has multiple SQL injection and CSRF vulnerabilities. The MailerLite Sign Up Form WordPress plugin makes it easy to grow your newsletter subscriber list from your WordPress blo...
- Multistage WordPress Redirect Kit
Research Sucuri, 8 Sep 2021
Recently, one of our analysts @kpetku came across a series of semi-randomised malware injections in multiple WordPress environments. Typical of spam redirect infections, the malware redirects visitors by calling malicious files hosted on...
- How To Report WordPress Security Vulnerabilities?
Research Patchstack, 30 Aug 2021
In this article, we will explain how to report WordPress security vulnerabilities to both Patchstack open database and manually to the vendors or the WordPress security team. In 2020 nearly 600 unique security vulnerabilities were found ...
- How Passwords Get Hacked
Research Sucuri, 26 Aug 2021
Can you think of an online service that doesn’t require a password? Everything on the internet requires a password. However, constantly creating and remembering new and ever more complex passwords is no small task. In fact, 66% of people...
- A Short History of Essay Spam (How We Got from Pills to Plagiarism)
Research Sucuri, 18 Aug 2021
From answering beginner questions like ‘ What is SEO spam? ’ to breaking down the spammers’ code and exactly how they hide their injections in compromised websites, we have written regularly about spam at Sucuri. If you’ve ever operated ...
- Best Practices for Web Form Security
Research Sucuri, 11 Aug 2021
Web form security - the set of tools and practices intended to protect web forms from attacks and abuse - is one of the most critical aspects of overall website security. Web forms allow users to interact with your site and enable a lo...
- Examining Unique Magento Backdoors
Research Sucuri, 4 Aug 2021
During a recent investigation into a compromised Magento ecommerce environment, we discovered the presence of five different backdoors that would provide attackers with code execution capabilities. The techniques used by the attackers in...
- Hackuu - The WordPress Security Legend Joined Patchstack
Research Patchstack, 4 Aug 2021
This summer has been something else. The world has changed over the past years. The internet has changed. WordPress ecosystem has been needing a hero, someone who could keep everybody safe in these uncertain times. Our hero has been hidi...
- Vulnerable Plugin Exploited in Spam Redirect Campaign
Research Sucuri, 21 Jul 2021
Some weeks ago a critical unauthenticated privilege escalation vulnerability was discovered in old, unpatched versions of the wp-user-avatar plugin. It also allows for arbitrary file uploads, which is where we have been seeing the infect...
- Critical WooCommerce SQL Injection Vulnerability Details
Research Patchstack, 15 Jul 2021
This security advisory is written about the WooCommerce SQL Injection vulnerability. Patchstack users are safe from the vulnerability. Update July 16th, 2021: we have seen a few attacks starting to happen around the evening time on July ...
- An Overview of Basic WordPress Hardening
Research Sucuri, 14 Jul 2021
We have discussed in the past how out-of-the-box security configurations tend to not be very secure. This is usually true for all software and WordPress is no exception. While there are a plethora of different ways that site owners can l...
- WordPress Bug Hunt 2021
Research Patchstack, 1 Jul 2021
Over the past 2 months, Patchstack Alliance has helped to identify and fix over 400 security vulnerabilities found in WordPress plugins and themes. We have monthly cash prizes for security researchers who report vulnerabilities to Patchs...
- Online Credit Card Theft - A Brief Overview of Online Fraud and Abuse - Part 2
Research Sucuri, 30 Jun 2021
In my previous post about ecommerce credit card swipers I described the general overview of the online ecommerce environment as well as some of the reasons behind why websites become compromised with this type of malware. In this post I ...
- Has My WordPress Site Been Hacked? A Guide To Read The Signs
Research Patchstack, 30 Jun 2021
This guide will help you give answers to the question - has my WordPress site been hacked? WordPress sites get hacked all the time, so you need to make sure that you can recognise the signs of a hack as soon as possible. To try and aid w...
- Why You Shouldn’t Be Using Nulled WordPress Themes And Plugins?
Research Patchstack, 29 Jun 2021
Nulled WordPress themes and nulled plugins appear as one of the biggest threats to WordPress security nowadays. One of the key features that have led to the success of WordPress is the wide range of available themes and plugins. There ar...
- How To Check Website For Spam Links And Pharma Spam?
Research Patchstack, 29 Jun 2021
In this guide, we’ll explain how pharma spam works. We will offer some tips for checking if you have any pharma spam on your website. Finally, we’ll share a few tips for securing your website against this kind of attack. What is pharma s...
- Google Dorking Exposes WordPress Vulnerabilities
Research Patchstack, 29 Jun 2021
What is Google Dorking? Google Dorking or Google Hacking is a search technique that involves advanced operators to craft specific search queries. These search queries could provide SERPs (Search Engine Results Pages) with a list of vulne...
- How To Check WordPress Sensitive Information Leakage And Stop It?
Research Patchstack, 29 Jun 2021
This blog post explains what is WordPress sensitive information leakage, what risks it includes, and how to stop it. Hackers often use search engines like Google to find WordPress websites with vulnerabilities. Once with a website with a...
- How Do Websites Get Hacked? The Most Common Website Hacking Techniques
Research Patchstack, 29 Jun 2021
This guide will share the most common website hacking techniques to help you prepare for malicious attacks. The lucrative nature of the Internet has led to a significant increase in the number of website hacking techniques. Cybercriminal...
- How To Protect Site From Malware Upload By File Upload Form
Research Patchstack, 28 Jun 2021
This article explains how to protect your website from malware upload by File Upload Form. Statistics show that file upload vulnerabilities are WordPress’s third most common vulnerability type. Hackers will often use file upload vulnerab...
- How To Remove WordPress Redirects?
Research Patchstack, 21 Jun 2021
This blog post explains how to remove redirects in WordPress. To remove WordPress redirects you should know how redirections work. One common attack vector used against WordPress websites involves compromising files to cause the website ...
- Malicious Redirects Through Bogus Plugin
Research Sucuri, 17 Jun 2021
Recently we have been seeing a rash of WordPress website compromises with attackers abusing the plugin upload functionality in the wp-admin dashboard to redirect visitors and website owners to malicious websites. The payload is the follo...
- What Is A Brute-Force Attack?
Research Patchstack, 17 Jun 2021
Every day, countless WordPress websites face automated login attempts from malicious bots. In 2023 alone, thousands of WordPress sites fell victim to successful brute-force attacks, leading to data breaches, malware infections, and signi...
- Patchstack Can Now Assign CVE IDs As New CVE Numbering Authority (CNA)
Research Patchstack, 16 Jun 2021
We are thrilled to finally announce that as of June 2021, Patchstack has been named by the Common Vulnerabilities and Exposures (CVE®) Program as a CNA (CVE Numbering Authority). As a CVE Numbering Authority, Patchstack is authorized to ...
- What To Do If Your Website Is Flagged For Malware By Google?
Research Patchstack, 16 Jun 2021
This blog post gives information and a step-by-step guide on how to act and clean your site after your website is flagged for malware by Google. Google is very proactive when it comes to protecting the safety of its customers. They scan ...
- How Poor Coding Puts WordPress Sites at Risk of Hacking
Research Patchstack, 16 Jun 2021
WordPress is the world’s most popular content management system. Over 835 million websites use it, and nearly 22% of new U.S. registered domains install WordPress. In recent years, WordPress has faced some criticism for its use of PHP an...
- 10Web Now Partnering With Patchstack
Research Patchstack, 15 Jun 2021
We are excited to announce that 10Web and Patchstack have partnered up. We are working together with 10Web to help strengthen the WordPress ecosystem. 10Web has joined Patchstack in a mission to make WordPress security information more a...
- CIA Triad From WordPress And WooCommerce Security Perspective
Research Patchstack, 15 Jun 2021
CIA triad is an abbreviation for confidentiality, integrity, and availability. The CIA triad is considered to be the basis for all information security models. Confidentiality, integrity, and availability are crucial to ensuring the secu...
- The Principle Of Least Privilege (POLP) In WordPress
Research Patchstack, 15 Jun 2021
Imagine waking up to find your WordPress site hacked, your business’s reputation tarnished, and revenue plummeting. Scary, right? Maintaining a high level of security is essential to running a successful WordPress website. Failure to do ...
- Test WordPress Plugin Security: Are All Plugins On WordPress.org Safe?
Research Patchstack, 14 Jun 2021
This blog post focuses on giving you information about how to test WordPress plugin security with a checklist of tasks. It also explains if all the plugins you find from the WordPress plugin repository are safe or not. Right now, you hav...
- Why WordPress Sites Get Hacked?
Research Patchstack, 14 Jun 2021
The focus of this blog post is to explain how and why WordPress sites get hacked. Firstly, WordPress is the most popular content management system (CMS) in the world, by far. Almost 40 percent of all websites in the world run on WordPres...
- Patchstack Red Team Prize Pool Increased To $1500 USD In June
Research Patchstack, 11 Jun 2021
UPDATE: As of 2022, Patchstack Red Team is known as Patchstack Alliance Patchstack Red Team is the most active bug hunting community for security researchers to earn prizes for finding new vulnerabilities in WordPress core, themes, and p...
- WordPress Redirect Hack via Test0.com/Default7.com
Research Sucuri, 4 Jun 2021
Malicious redirect is a type of hack where website visitors are automatically redirected to some third-party website: usually it’s some malicious resource, scam site or a commercial site that buys traffic from cyber criminals (e.g. count...
- WooCommerce Credit Card Skimmer Hides in Plain Sight
Research Sucuri, 28 May 2021
Recently, a client’s customers were receiving a warning from their anti-virus software when they navigated to the checkout page of the client’s ecommerce website. Antivirus software such as Kaspersky and ESET would issue a warning but on...
- Veebimajutus Now Partnering With Patchstack
Research Patchstack, 21 May 2021
We are excited to announce that an Estonian hosting service Veebimajutus and Patchstack have partnered up. The aim of this partnership is to help strengthen the WordPress ecosystem by giving WordPress site owners, agencies and developers...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.