Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,886 reports kept since 2009. Updated automatically every 10 minutes. Last checked 6 min ago.

  1. Fake WordPress Functions Conceal assert() Backdoor

    Research Sucuri, 8 Dec 2020

    A few weeks ago, I was manually inspecting some files on a compromised website. While checking on a specific WooCommerce file, I noticed something interesting. Among 246 other lines, this very specific part stood out to me: $config = wp_...

  2. Obfuscation Techniques in MARIJUANA Shell “Bypass”

    Research Sucuri, 4 Dec 2020

    Attackers are always trying to come up with new ways to evade detection from the wide range of security controls available for web applications. This also extends to malware like PHP web shells, which are typically left on compromised we...

  3. “Free” Symchanger Malware Tricks Users Into Installing Backdoor

    Research Sucuri, 1 Dec 2020

    In a previous post, I discussed how attackers can trick website owners into installing malware onto a website - granting the attacker the same unauthorized access as if they had exploited a vulnerability or compromised login details for ...

  4. Hackers Love Expired Domains

    Research Sucuri, 26 Nov 2020

    Sometimes, website owners no longer want to own a domain name and they allow it to expire without attempting to renew it. This happens all the time and is totally normal, but it’s important to remember that attackers regularly monitor do...

  5. Hidden SEO Spam Link Injections on WordPress Sites

    Research Sucuri, 23 Nov 2020

    Often when a website is injected with SEO spam, the owner is completely unaware of the issue until they begin to receive warnings from search engines or blacklists. This is by design - attackers intentionally try to prevent detection by ...

  6. PrestaShop SuperAdmin Injector and Login Stealer

    Research Sucuri, 18 Nov 2020

    According to W3Tech’s data, PrestaShop is among the most popular CMS choices for existing ecommerce websites, so it should come as no surprise that malware has been created to specifically target these environments. We recently came acro...

  7. Evasive Maneuvers in Data Stealing Gateways

    Research Sucuri, 17 Nov 2020

    We have already shared examples of many kinds of malware that rely on an external gateway to receive or return data, such as different malware payloads. During a recent investigation, we came across this example of a PHP script that atta...

  8. Another Credit Card Stealer That Pretends to Be Sucuri

    Research Sucuri, 12 Nov 2020

    During a routine investigation, we found yet another web skimmer that pretends to be related to Sucuri. One of our Remediation Analysts, Liam Smith, found the following code injected into the database of a Magento site. The first 109 lin...

  9. Code Comments Reveal SCP 173 Malware

    Research Sucuri, 10 Nov 2020

    We sometimes find malware code injections that contain strange code comments, which are normally used by programmers to annotate a section of code - for example, a short description of a feature or functionality for other developers to r...

  10. Legacy Mauthtoken Malware Continues to Redirect Mobile Users

    Research Sucuri, 5 Nov 2020

    During malware analysis, we regularly find variations of this injected script on various compromised websites: . The variable “ _0x446d ” assigns hex encoded strings in different positions in the array. If we get the ASCII representation...

  11. CSS-JS Steganography in Fake Flash Player Update Malware

    Research Sucuri, 2 Nov 2020

    This summer, MalwareBytes researcher Jérôme Segura wrote an article about how criminals use image files (.ico) to hide JavaScript credit card stealers on compromised e-commerce sites. In a tweet, Affable Kraut also reported another simil...

  12. Reflected XSS in WordPress v5.5.1 and Lower

    Research Sucuri, 30 Oct 2020

    WordPress released version 5.5.2 yesterday, which fixed a reflected XSS vulnerability we reported earlier this year. The root cause of this issue is a bug in the way WordPress determines a user’s current page, and which may cause a few o...

  13. Bridging the Gap Between Application and Network Security with CleanBrowsing

    Research Sucuri, 30 Oct 2020

    When we started Sucuri we set out to make enterprise security accessible, affordable, and effective for every day webmasters. It was at a time when open-source platforms like WordPress, Joomla!, Drupal, and others were changing the web l...

  14. 5 Places Where You’d Never Expect to Get Hacked

    Research Sucuri, 28 Oct 2020

    For every gleaming new IoT device that hits the market, a hacker somewhere is figuring out how to compromise it. Today, even routine activities can land you in the sights of a bad actor. Imagine what a bad day could look like in this era...

  15. R_Evil WordPress Hacktool & Malicious JavaScript Injections

    Research Sucuri, 22 Oct 2020

    We often see hackers reusing the same malware, with only a few new adjustments to obfuscate the code so that it is more difficult for scanning tools to detect. However, sometimes entirely new attack tools are created and deployed by thre...

  16. Sucuri Sit-Down Episode 4: XSS & WP Plugin Vulnerabilities with Antony Garand

    Research Sucuri, 15 Oct 2020

    October is National Cyber Security Awareness Month, and we’re back with analyst Antony Garand to take a deeper look into cross site scripting (XSS) attacks and WordPress plugin vulnerabilities. Plus, host Justin Channell will catch you u...

  17. Magento Phishing Leverages JavaScript For Exfiltration

    Research Sucuri, 14 Oct 2020

    During a recent investigation, a Magento admin login phishing page was found on a compromised website using the file name wp-order.php . This is an odd file name choice for a Magento phishing page, but nevertheless it successfully loads ...

  18. Redirects to YouTube Defacement Channel

    Research Sucuri, 13 Oct 2020

    During a recent investigation, we found an infected website was redirecting to YouTube after its main index.php file had been modified to include the following line of HTML: This technique works because it’s possible to use HTML within ....

  19. Backdoor Shell Dropper Deploys CMS-Specific Malware

    Research Sucuri, 6 Oct 2020

    A large majority of the malware we find on compromised websites are backdoors that allow an attacker to maintain unauthorized access to the site and execute whatever commands they want. Another common scenario includes malware which is d...

  20. GFX Xsender Hack Tool: A Spam Mailer

    Research Sucuri, 1 Oct 2020

    PHP hack tools are created and used by attackers to help automate frequent or tedious tasks. During a recent investigation, we came across a hack tool used to simplify the process of sending predefined HTML emails to a list of email addr...

  21. Malicious Pop-up Redirects Baidu Traffic

    Research Sucuri, 29 Sep 2020

    Malicious pop-ups and redirects have become two extremely common techniques used by attackers to drive traffic wherever they want. \ During a recent investigation, we came across an obfuscated pop-up script leveraging baidu[.]com search ...

  22. Backdoor Obfuscation: tempnam & URL Encoding

    Research Sucuri, 28 Sep 2020

    In an attempt to avoid detection, attackers and malware authors are always experimenting with different methods to obfuscate their malicious code. During a recent investigation, we came across an interesting backdoor that was leveraging ...

  23. Magento Credit Card Stealing Malware: gstaticapi

    Research Sucuri, 25 Sep 2020

    Our team recently came across a malicious script used on a Magento website titled gstaticapi, which targeted checkout processes to capture and exfiltrate stolen information. To obtain sensitive details, the malware loads external javascr...

  24. Malicious One-Liner Using Hastebin

    Research Sucuri, 23 Sep 2020

    Short scripts that deliver malware to a website are nothing new, but during a recent investigation we found a script using hastebin[.]com , which is a domain we see used infrequently. The script was found writing malicious contents into ...

  25. The Hidden PHP Malware that Reinfects Cleaned Files

    Research Sucuri, 18 Sep 2020

    Website reinfections are a serious problem for website owners, and it can often be difficult to determine the cause behind the reinfection - especially if you lack access to necessary logs, which is usually the case for shared hosting se...

  26. phpbash - A Terminal Emulator Web Shell

    Research Sucuri, 16 Sep 2020

    It’s common for hackers to utilize post-compromise tools that contain a graphical user interface (GUI) that can be loaded in the web browser. A GUI generally makes the tool easier to use - and certainly more visually appealing than just ...

  27. WordPress Malware Disables Security Plugins to Avoid Detection

    Research Sucuri, 10 Sep 2020

    An alarm or monitoring system is a great tool that can be used to improve the security of a home or website, but what if an attacker can easily disable it? I’ve previously written about malware that reverses security hardening measures e...

  28. Reflected XSS in WordPress Plugin Admin Pages

    Research Sucuri, 8 Sep 2020

    The administrative dashboard in WordPress is a pretty safe place: Only elevated users can access it. Exploiting a plugin’s admin panel would serve very little purpose here - an administrator already has the required permissions to do all...

  29. Insufficient Privilege Validation in NextScripts: Social Networks Auto-Poster

    Research Sucuri, 4 Sep 2020

    NextScripts: Social Networks Auto-Poster is a plugin that automatically publishes posts from your blog to your Social Media accounts such as Facebook, Twitter, Google+, Blogger, Tumblr, Flickr, LinkedIn, Instagram, Telegram, YouTube, Wor...

  30. Critical Vulnerability in File Manager Plugin Affecting 700k WordPress Websites

    Research Sucuri, 2 Sep 2020

    Yesterday, the WordPress plugin File Manager was updated, fixing a critical vulnerability allowing any website visitor to gain complete access to the website. Users of our WAF were never vulnerable to this exploit. The Sucuri firewall bl...

  31. Using assert() to Execute Malware in PHP 7 Environments

    Research Sucuri, 1 Sep 2020

    Initially released December 2015, PHP 7 introduced a multitude of performance and security improvements. Approximately 43.7% of websites across the web currently use PHP 7.x, making it an incredibly popular scripting language - which is ...

  32. Persistent WordPress User Injection

    Research Sucuri, 28 Aug 2020

    Our team recently stumbled across an interesting example of malicious code used to add an arbitrary user inside WordPress. The following code was detected at the bottom of the theme’s functions.php. I t uses internal WordPress functions ...

  33. Magento Multiversion (1.x/2.x) Backdoor

    Research Sucuri, 26 Aug 2020

    The Magento 1 EOL date has already passed, however it’s evident that a large number of websites will continue to use it for the foreseeable future. Unfortunately, attackers are also aware that many websites are struggling with their Mage...

  34. Multiple Vulnerabilities In Discount Rules for WooCommerce Plugin

    Research Patchstack, 20 Aug 2020

    There are SQLi and unauthenticated stored XSS vulnerabilities in Discount Rules for the WooCommerce WordPress plugin. The Discount Rules for the WooCommerce plugin (versions 2.0.2 and below) suffer from multiple vulnerabilities such as S...

  35. CDN-Filestore Credit Card Stealer for Magento

    Research Sucuri, 18 Aug 2020

    During a website remediation, we recently discovered a new version of a Magento credit card stealer which sends all compromised data to the malicious domain cdn-filestore[dot]com . My colleague Luke Leal originally wrote about this malwa...

  36. Web Crawler & User Agent Blocking Techniques

    Research Sucuri, 14 Aug 2020

    This is a simple script that allows hackers to block specific crawlers based upon website requests from specific user-agents. This is useful when you don’t want certain traffic from being able to load certain content - usually a phishing...

  37. Smoker Backdoor: Evasion Techniques in Webshell Backdoors

    Research Sucuri, 13 Aug 2020

    “Smoker Backdoor” is a PHP webshell backdoor that uses hexadecimal and decimal obfuscation in conjunction with the PHP function goto to evade detection from malware scanners. The hexadecimal/decimal obfuscation is clear to see when viewi...

  38. String Concatenation: Obfuscation Techniques

    Research Sucuri, 12 Aug 2020

    While string concatenation has many valuable applications in development - such as making code more efficient or functions more effective - it is also a popular way for attackers to obfuscate code and try to make it more difficult to det...

  39. PHP Binary Downloader

    Research Sucuri, 7 Aug 2020

    When possible, an attacker will want to avoid using specific functions in their PHP code that they know are more likely to be flagged by a scanner. Some examples of suspicious functions commonly detected include system and file_put_conte...

  40. PHP Backdoor Obfuscated One Liner

    Research Sucuri, 5 Aug 2020

    In the past, I have explained how small one line PHP backdoors use obfuscation and strings of code in HTTP requests to pass attacker’s commands to backdoors. Today, I’ll highlight another similar injection example and describe some of th...

  41. Vulnerabilities Digest: July 2020

    Research Sucuri, 3 Aug 2020

    Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs Asset CleanUp: Page Speed Authenticated XSS 1.4.6.7 80000 Quiz And Survey Master Authenticated Stored XSS 7.0.0 30000 Comments - wpDiscuz 7.0.0 - Arbitra...

  42. SEO Hacktool: Sitemap Generator

    Research Sucuri, 30 Jul 2020

    An XML sitemap is an important part of a website’s SEO and exists to help search engine crawlers index new URLs on your website. For example, if a site has a large number of pages that were recently updated and the owner wants Google to ...

  43. Reverse String WooCommerce WordPress Credit Card Swiper

    Research Sucuri, 27 Jul 2020

    As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential dread even further. As a sequel to my last blog post earlier this year about the credit card sw...

  44. Skimmers in Images & GitHub Repos

    Research Sucuri, 22 Jul 2020

    MalwareBytes recently shared some information about web skimmers that store malicious code inside real .ico files. During a routine investigation, we detected a similar issue. Instead of targeting .ico files, however, attackers chose to ...

  45. Fake WordPress Plugin SiteSpeed Serves Malicious Ads & Backdoors

    Research Sucuri, 16 Jul 2020

    Fake WordPress plugins appear to be trending as an effective way of establishing a foothold on compromised websites. During a recent investigation, we discovered a fake component which was masquerading as a legitimate plugin. Named SiteS...

  46. Pirated WordPress Plugins Bundled with Backdoors

    Research Sucuri, 8 Jul 2020

    One widespread belief among webmasters is that attackers typically only compromise websites in a couple of ways: by exploiting vulnerabilities or stealing login credentials. Although these are certainly two of the more common attack vect...

  47. Vulnerabilities Digest: June 2020

    Research Sucuri, 6 Jul 2020

    Highlights for June 2020 Cross site scripting is still the most common vulnerability in WordPress Plugins. Bad actors are taking advantage of the lack of restrictions in critical functions and issues surrounding user input data sanitizat...

  48. Sucuri Sit-Down Episode 2: Malware Types Explained with Krasimir Konov

    Research Sucuri, 24 Jun 2020

    Malware comes in many different varieties. Analyst Krasimir Konov is on this month’s Sucuri Sit-Down to help keep them all straight. From malicious iframes to SEO spam, join host Justin Channell as he racks Krasimir’s brain on all the di...

  49. Cross Site Scripting in YITH WooCommerce Ajax Product Filter

    Research Sucuri, 22 Jun 2020

    During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+ users of the YITH WooCommerce Ajax Product Filter plugin. Current State of the Vulnerabi...

  50. Vulnerable Plugins: June 2020 Update

    Research Sucuri, 19 Jun 2020

    This is a mid-month update to our regular Monthly Vulnerability Digest , which reveals a number of new patches for disclosed vulnerabilities. Plugin Vulnerability Patched Version Installs Elementor Page Builder Authenticated Stored XSS 2...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support