HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 8 min ago.
- Object Injection Vulnerability Affects WordPress Versions 3.7 to 5.7.1
Research Sucuri, 17 May 2021
If you haven’t updated your WordPress website since October 2013, this wouldn’t affect you, but we strongly hope that is not the case! There’s a new object injection vulnerability which affects WordPress versions 3.7 to 5.7.1. Be sure to...
- WPScan Intro: How to Scan for WordPress Vulnerabilities
Research Sucuri, 7 May 2021
In this post, we look at how to use WPScan. The tool provides you a better understanding of your WordPress website and its vulnerabilities. Be sure to check out our post on installing WPScan to get started with the software. Contents: Ho...
- SecuPress Now Partnering With Patchstack
Research Patchstack, 7 May 2021
We are excited to announce that SecuPress and Patchstack have partnered up. The aim of this partnership is to help strengthen the WordPress ecosystem and its security by working together. SecuPress has joined Patchstack in a mission to m...
- Cloudways Now Partnering With Patchstack
Research Patchstack, 6 May 2021
We are excited to announce that Cloudways and Patchstack have partnered up. The aim of this partnership is to help strengthen the WordPress ecosystem by creating opportunities for WordPress developers. Cloudways has joined Patchstack in ...
- Shield Security Now Partnering With Patchstack
Research Patchstack, 5 May 2021
We are excited to announce that Shield Security and Patchstack have partnered up to combine the efforts to build a strong security community behind the WordPress ecosystem. Shield Security is supporting Patchstack Alliance and therefore ...
- Patchstack Red Team Prize Pool Increased To $1300 USD
Research Patchstack, 4 May 2021
UPDATE: As of 2022, Patchstack Red Team is known as Patchstack Alliance Patchstack Red Team is a community of independent security researchers who contribute to building a safer web. Red Team members identify and report security vulnerab...
- Social Warfare XSS and RCE Vulnerabilities and Attack Data
Research Patchstack, 29 Apr 2021
March 26, 2019 by Oliver Sild An unnamed security researcher publicly disclosed security vulnerabilities in the popular WordPress plugin Social Warfare. Which according to WordPress Plugins repository currently had over 70,000 active ins...
- [Survey] Website Security Issues And Challenges Explained
Research Patchstack, 28 Apr 2021
This article focused on the website security issues and challenges developers face. You can find out what are the main challenges web professionals face in 2020 and during the time of crisis. A wide range of attacks has been targeting bu...
- WPScan Intro: How to Install the WordPress Vulnerability Scanner
Research Sucuri, 21 Apr 2021
What does your WordPress site look like to hackers? Would it be tough to crack? Or does it have unlocked doors and unlatched windows just waiting for someone to try them? If you want to run a security test on your WordPress site that’ll ...
- Plugins And Themes Responsible For 96% Of WordPress Security 2020 Vulnerabilities
Research Patchstack, 20 Apr 2021
WordPress is the most popular content management system in the world. Just recently, it reached a milestone of powering 41% of the websites on the whole web. With such a scale, security is increasingly important. For that reason, we did ...
- WordPress Continues to Fall Victim to Carding Attacks
Research Sucuri, 14 Apr 2021
Unsurprisingly, as WordPress continues to increase in popularity as an e-commerce platform, attackers continue to attempt to steal credit card information from unsuspecting clients. Currently, the WordPress plugin WooCommerce accounts fo...
- Website Malware Removal - Using a Security Plugin, But Still Got Hacked?
Research Patchstack, 12 Apr 2021
In this article, we will look into common attack vectors that are not covered by any web application firewalls or security plugins. As a web developer or a website owner, it’s important for you to know that your sites are properly protec...
- PHP Repository Exploited by Hackers
Research Sucuri, 29 Mar 2021
The official PHP git repository, http://git.php.net/, was compromised this Sunday, March 28. An attacker was able to modify the PHP source code twice and inject a backdoor into it. Thankfully, both attempts were quickly detected and remo...
- How Do Websites Get Hacked?
Research Sucuri, 25 Mar 2021
As much as the web has grown, surprisingly not a lot has changed in how websites get hacked. The most important thing you can do in keeping the web - and your own sites and visitors - safe is to understand these unchanging truths and hol...
- How to secure a WordPress site with Patchstack?
Research Patchstack, 22 Mar 2021
This blog post will give you a complete step-by-step tutorial on how to secure a WordPress site with Patchstack. If you care about your business you need protection from hackers and for this, you need to have a complete overview of your ...
- Server Side Data Exfiltration via Telegram API
Research Sucuri, 18 Mar 2021
One of the themes commonly highlighted on this blog includes the many creative methods and techniques attackers employ to steal data from compromised websites. Credit card skimmers, credential and password hijackers, SQL injections, and ...
- Magento 2 PHP Credit Card Skimmer Saves to JPG
Research Sucuri, 10 Mar 2021
Bad actors often leverage creative techniques to conceal malicious behaviour and harvest sensitive information from ecommerce websites. A recent investigation for a compromised Magento 2 website revealed a malicious injection that was ca...
- Should I Rely On Web Hosting Security?
Research Patchstack, 5 Mar 2021
Over the years of being in the web security business, we have often seen people ask if web hosting security is all they need. Whether you are on the lookout for the cheapest hosting, shared hosting, cloud hosting or WordPress managed hos...
- 12 Website Security Tips From Experts
Research Patchstack, 5 Mar 2021
We have gathered 12 website security tips from experts to keep in mind. Security is something people and companies of any size cannot ignore and our mission is to make it as elementary as locks on home doors. People may not think that th...
- 5 Reasons Why Website Security Is Important
Research Patchstack, 4 Mar 2021
By some estimates, about 30 000 to 50 000 websites get hacked every day. The numbers are growing daily and the importance of website security is increasing rapidly. Being secure in the online world becomes more and more important every d...
- The Definitive Guide to Logs for WordPress Administrators
Research Patchstack, 3 Mar 2021
Logs for WordPress administrators - the definitive guide to all the logs WordPress site administrators can use. Logs are like unsung heroes; they store a wealth of information and have an important role in any type of software, yet they ...
- My Website Got Hacked! What To Do Now?
Research Patchstack, 26 Feb 2021
Has that ever happened to you that your website got hacked? This is a story about how Toms website got hacked, actually, multiple websites got hacked. According to statistics, over 30,000 websites get hacked every day and even a regular ...
- René Andersen: I Have No Problem Of Website Infections
Research Patchstack, 26 Feb 2021
Web designer and graphic designer René Andersen shares why his sites are protected by Patchstack and how Patchstack helps him to stay away from website infections or malware problems. René has a one-man business. He is creating awesome d...
- Support Meow: Hacked Websites Mean Lost Revenue
Research Patchstack, 26 Feb 2021
“Hacked websites mean lost revenue.” - Silver from Support Meow Silver helps WordPress owners with site management. He shares why his sites are protected by Patchstack and how Patchstack helps him to give his customers better service. Si...
- SQL Triggers in Website Backdoors
Research Sucuri, 25 Feb 2021
Over the past year, there’s been an increasing trend of WordPress malware using SQL triggers to hide malicious SQL queries within hacked databases. These queries inject an admin level user into the infected database whenever the trigger ...
- Critical Vulnerability in Easy WP SMTP WordPress Plugin
Research Patchstack, 25 Feb 2021
There is a password reset vulnerability caused by a data leak from a debug log file in the WordPress plugin Easy WP SMTP. Several hours ago, “WP eCommerce” released Easy WP SMTP WordPress plugin version 1.4.3 which patches the easily exp...
- Multiple Vulnerabilities In WordPress Plugin Popup Builder
Research Patchstack, 25 Feb 2021
The Popup Builder - Responsive WordPress Pop up - Subscription & Newsletter plugin (versions 3.71 and below) suffers from a lack of authorization in most AJAX methods. The Popup Builder WordPress plugin has 200 000+ active installations ...
- Bitcoin Ransom Scam Targeting Website Owners
Research Patchstack, 25 Feb 2021
A new wave of bitcoin ransom scam has been reported which targets website owners by claiming their sites to be hacked and asking 1500 - 3000 USD worth of bitcoins. Scammers push a narrative that the database of the website has been extra...
- HTTP Security Headers for WordPress: A Comprehensive Guide
Research Patchstack, 25 Feb 2021
Security misconfiguration has long been a top concern for website security, and in 2021, the OWASP Top 10 team highlighted it as one of the most common reasons websites are hacked. Among the potential misconfigurations, security headers ...
- How Your Hacked Website Can Affect Your Visitors?
Research Patchstack, 23 Feb 2021
Your website will always be a vital component of your business, service, or cause. However, a hacked website will cause an overflow of complications for both you and your visitors. This post will shed more light on how your hacked websit...
- Why Are Hackers Attacking Websites?
Research Patchstack, 23 Feb 2021
The problem with hackers attacking websites is on a constant rise. Month-to-month we list tens of vulnerabilities found in popular plugins that developers use on their sites. Most of these are being targeted by hackers. We monitor the si...
- Website Hacking Statistics You Should Know in 2022
Research Patchstack, 22 Feb 2021
In this article, you can read about the latest website hacking statistics from 2022. These updated statistics on website hacking should give you an idea of just how difficult it is to ensure website security each passing year. Any softwa...
- Optimizing Performance and Behavior with WordPress and the Sucuri WAF
Research Sucuri, 9 Feb 2021
Aside from providing significant protection from a wide range of threats, the Sucuri WAF also acts as a CDN due to its caching capabilities and regional PoPs - often performing even better than dedicated CDNs based on recent tests. CDNs ...
- Whitespace Steganography Conceals Web Shell in PHP Malware
Research Sucuri, 2 Feb 2021
Last November, we wrote about how attackers are using JavaScript injections to load malicious code from legitimate CSS files. At first glance, these injections didn’t appear to contain anything except for some benign CSS rules. A more th...
- Magento PHP Injection Loads JavaScript Skimmer
Research Sucuri, 21 Jan 2021
A Magento website owner was concerned about malware and reached out to our team for assistance. Upon investigation, we found the website contained a PHP injection in one of the Magento files: ./app/code/core/Mage/Payment/Model/Method/Cc....
- Critical Vulnerabilities in 123contactform-for-wordpress WordPress Plugin
Research Sucuri, 19 Jan 2021
In mass infection scenarios, our Malware Research team often looks for attack vectors to find patterns and other similarities among compromised websites. The identification of these patterns allows us to deploy better and faster solution...
- Evaluating Cookies to Hide Backdoors
Research Sucuri, 7 Jan 2021
Identifying website backdoors is not always an easy task. Since a backdoors primary function is to conceal itself while providing unauthorized access, they are often developed using a variety of techniques that can make it challenging to...
- Bogus CSS Injection Leads to Stolen Credit Card Details
Research Sucuri, 5 Jan 2021
A client recently reported their customers were receiving antivirus warnings when trying to access and purchase products from a Magento ecommerce website. This is almost always a telltale sign that something is amiss, and so I began my i...
- SEO Spam Links in Nulled Plugins
Research Sucuri, 29 Dec 2020
It’s not unusual to see website owners running things on a budget. Choosing a safe and reliable hosting company, buying a nice domain name, boosting posts on social media, and ranking on search engines - all this costs a lot of money. At...
- The Dangers of Using Abandoned Plugins & Themes
Research Sucuri, 17 Dec 2020
It’s not very often that we see abandoned components being used on a website - but when we do, it’s most often because the website was exhibiting malware-like behavior and we were called to investigate and clean up the site. Old and aban...
- Why You Should Monitor Your Website
Research Sucuri, 15 Dec 2020
In an effort to maintain unauthorized access or profit off a website’s environment long after an initial compromise, attackers commonly leverage a variety of different techniques and tactics. These techniques range from adding backdoors,...
- Malware Dropper Takes Advantage of COVID-19 Pandemic
Research Sucuri, 10 Dec 2020
Since April, our team has been tracking the spread of a PHP malware dropper. It’s impacting unsuspecting victims who thought they were downloading a mapping software to monitor the spread of the COVID-19 pandemic. While the attack is lik...
- Fake WordPress Functions Conceal assert() Backdoor
Research Sucuri, 8 Dec 2020
A few weeks ago, I was manually inspecting some files on a compromised website. While checking on a specific WooCommerce file, I noticed something interesting. Among 246 other lines, this very specific part stood out to me: $config = wp_...
- Obfuscation Techniques in MARIJUANA Shell “Bypass”
Research Sucuri, 4 Dec 2020
Attackers are always trying to come up with new ways to evade detection from the wide range of security controls available for web applications. This also extends to malware like PHP web shells, which are typically left on compromised we...
- “Free” Symchanger Malware Tricks Users Into Installing Backdoor
Research Sucuri, 1 Dec 2020
In a previous post, I discussed how attackers can trick website owners into installing malware onto a website - granting the attacker the same unauthorized access as if they had exploited a vulnerability or compromised login details for ...
- Hackers Love Expired Domains
Research Sucuri, 26 Nov 2020
Sometimes, website owners no longer want to own a domain name and they allow it to expire without attempting to renew it. This happens all the time and is totally normal, but it’s important to remember that attackers regularly monitor do...
- Hidden SEO Spam Link Injections on WordPress Sites
Research Sucuri, 23 Nov 2020
Often when a website is injected with SEO spam, the owner is completely unaware of the issue until they begin to receive warnings from search engines or blacklists. This is by design - attackers intentionally try to prevent detection by ...
- PrestaShop SuperAdmin Injector and Login Stealer
Research Sucuri, 18 Nov 2020
According to W3Tech’s data, PrestaShop is among the most popular CMS choices for existing ecommerce websites, so it should come as no surprise that malware has been created to specifically target these environments. We recently came acro...
- Evasive Maneuvers in Data Stealing Gateways
Research Sucuri, 17 Nov 2020
We have already shared examples of many kinds of malware that rely on an external gateway to receive or return data, such as different malware payloads. During a recent investigation, we came across this example of a PHP script that atta...
- Another Credit Card Stealer That Pretends to Be Sucuri
Research Sucuri, 12 Nov 2020
During a routine investigation, we found yet another web skimmer that pretends to be related to Sucuri. One of our Remediation Analysts, Liam Smith, found the following code injected into the database of a Magento site. The first 109 lin...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.