Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeLatest WordPress security threats

Latest WordPress security threats

This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.

1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.

  1. Code Comments Reveal SCP 173 Malware

    Research Sucuri, 10 Nov 2020

    We sometimes find malware code injections that contain strange code comments, which are normally used by programmers to annotate a section of code - for example, a short description of a feature or functionality for other developers to r...

  2. Legacy Mauthtoken Malware Continues to Redirect Mobile Users

    Research Sucuri, 5 Nov 2020

    During malware analysis, we regularly find variations of this injected script on various compromised websites: . The variable “ _0x446d ” assigns hex encoded strings in different positions in the array. If we get the ASCII representation...

  3. CSS-JS Steganography in Fake Flash Player Update Malware

    Research Sucuri, 2 Nov 2020

    This summer, MalwareBytes researcher Jérôme Segura wrote an article about how criminals use image files (.ico) to hide JavaScript credit card stealers on compromised e-commerce sites. In a tweet, Affable Kraut also reported another simil...

  4. Reflected XSS in WordPress v5.5.1 and Lower

    Research Sucuri, 30 Oct 2020

    WordPress released version 5.5.2 yesterday, which fixed a reflected XSS vulnerability we reported earlier this year. The root cause of this issue is a bug in the way WordPress determines a user’s current page, and which may cause a few o...

  5. Bridging the Gap Between Application and Network Security with CleanBrowsing

    Research Sucuri, 30 Oct 2020

    When we started Sucuri we set out to make enterprise security accessible, affordable, and effective for every day webmasters. It was at a time when open-source platforms like WordPress, Joomla!, Drupal, and others were changing the web l...

  6. 5 Places Where You’d Never Expect to Get Hacked

    Research Sucuri, 28 Oct 2020

    For every gleaming new IoT device that hits the market, a hacker somewhere is figuring out how to compromise it. Today, even routine activities can land you in the sights of a bad actor. Imagine what a bad day could look like in this era...

  7. R_Evil WordPress Hacktool & Malicious JavaScript Injections

    Research Sucuri, 22 Oct 2020

    We often see hackers reusing the same malware, with only a few new adjustments to obfuscate the code so that it is more difficult for scanning tools to detect. However, sometimes entirely new attack tools are created and deployed by thre...

  8. Sucuri Sit-Down Episode 4: XSS & WP Plugin Vulnerabilities with Antony Garand

    Research Sucuri, 15 Oct 2020

    October is National Cyber Security Awareness Month, and we’re back with analyst Antony Garand to take a deeper look into cross site scripting (XSS) attacks and WordPress plugin vulnerabilities. Plus, host Justin Channell will catch you u...

  9. Magento Phishing Leverages JavaScript For Exfiltration

    Research Sucuri, 14 Oct 2020

    During a recent investigation, a Magento admin login phishing page was found on a compromised website using the file name wp-order.php . This is an odd file name choice for a Magento phishing page, but nevertheless it successfully loads ...

  10. Redirects to YouTube Defacement Channel

    Research Sucuri, 13 Oct 2020

    During a recent investigation, we found an infected website was redirecting to YouTube after its main index.php file had been modified to include the following line of HTML: This technique works because it’s possible to use HTML within ....

  11. Backdoor Shell Dropper Deploys CMS-Specific Malware

    Research Sucuri, 6 Oct 2020

    A large majority of the malware we find on compromised websites are backdoors that allow an attacker to maintain unauthorized access to the site and execute whatever commands they want. Another common scenario includes malware which is d...

  12. GFX Xsender Hack Tool: A Spam Mailer

    Research Sucuri, 1 Oct 2020

    PHP hack tools are created and used by attackers to help automate frequent or tedious tasks. During a recent investigation, we came across a hack tool used to simplify the process of sending predefined HTML emails to a list of email addr...

  13. Malicious Pop-up Redirects Baidu Traffic

    Research Sucuri, 29 Sep 2020

    Malicious pop-ups and redirects have become two extremely common techniques used by attackers to drive traffic wherever they want. \ During a recent investigation, we came across an obfuscated pop-up script leveraging baidu[.]com search ...

  14. Backdoor Obfuscation: tempnam & URL Encoding

    Research Sucuri, 28 Sep 2020

    In an attempt to avoid detection, attackers and malware authors are always experimenting with different methods to obfuscate their malicious code. During a recent investigation, we came across an interesting backdoor that was leveraging ...

  15. Magento Credit Card Stealing Malware: gstaticapi

    Research Sucuri, 25 Sep 2020

    Our team recently came across a malicious script used on a Magento website titled gstaticapi, which targeted checkout processes to capture and exfiltrate stolen information. To obtain sensitive details, the malware loads external javascr...

  16. Malicious One-Liner Using Hastebin

    Research Sucuri, 23 Sep 2020

    Short scripts that deliver malware to a website are nothing new, but during a recent investigation we found a script using hastebin[.]com , which is a domain we see used infrequently. The script was found writing malicious contents into ...

  17. The Hidden PHP Malware that Reinfects Cleaned Files

    Research Sucuri, 18 Sep 2020

    Website reinfections are a serious problem for website owners, and it can often be difficult to determine the cause behind the reinfection - especially if you lack access to necessary logs, which is usually the case for shared hosting se...

  18. phpbash - A Terminal Emulator Web Shell

    Research Sucuri, 16 Sep 2020

    It’s common for hackers to utilize post-compromise tools that contain a graphical user interface (GUI) that can be loaded in the web browser. A GUI generally makes the tool easier to use - and certainly more visually appealing than just ...

  19. WordPress Malware Disables Security Plugins to Avoid Detection

    Research Sucuri, 10 Sep 2020

    An alarm or monitoring system is a great tool that can be used to improve the security of a home or website, but what if an attacker can easily disable it? I’ve previously written about malware that reverses security hardening measures e...

  20. Reflected XSS in WordPress Plugin Admin Pages

    Research Sucuri, 8 Sep 2020

    The administrative dashboard in WordPress is a pretty safe place: Only elevated users can access it. Exploiting a plugin’s admin panel would serve very little purpose here - an administrator already has the required permissions to do all...

  21. Insufficient Privilege Validation in NextScripts: Social Networks Auto-Poster

    Research Sucuri, 4 Sep 2020

    NextScripts: Social Networks Auto-Poster is a plugin that automatically publishes posts from your blog to your Social Media accounts such as Facebook, Twitter, Google+, Blogger, Tumblr, Flickr, LinkedIn, Instagram, Telegram, YouTube, Wor...

  22. Critical Vulnerability in File Manager Plugin Affecting 700k WordPress Websites

    Research Sucuri, 2 Sep 2020

    Yesterday, the WordPress plugin File Manager was updated, fixing a critical vulnerability allowing any website visitor to gain complete access to the website. Users of our WAF were never vulnerable to this exploit. The Sucuri firewall bl...

  23. Using assert() to Execute Malware in PHP 7 Environments

    Research Sucuri, 1 Sep 2020

    Initially released December 2015, PHP 7 introduced a multitude of performance and security improvements. Approximately 43.7% of websites across the web currently use PHP 7.x, making it an incredibly popular scripting language - which is ...

  24. Persistent WordPress User Injection

    Research Sucuri, 28 Aug 2020

    Our team recently stumbled across an interesting example of malicious code used to add an arbitrary user inside WordPress. The following code was detected at the bottom of the theme’s functions.php. I t uses internal WordPress functions ...

  25. Magento Multiversion (1.x/2.x) Backdoor

    Research Sucuri, 26 Aug 2020

    The Magento 1 EOL date has already passed, however it’s evident that a large number of websites will continue to use it for the foreseeable future. Unfortunately, attackers are also aware that many websites are struggling with their Mage...

  26. Multiple Vulnerabilities In Discount Rules for WooCommerce Plugin

    Research Patchstack, 20 Aug 2020

    There are SQLi and unauthenticated stored XSS vulnerabilities in Discount Rules for the WooCommerce WordPress plugin. The Discount Rules for the WooCommerce plugin (versions 2.0.2 and below) suffer from multiple vulnerabilities such as S...

  27. CDN-Filestore Credit Card Stealer for Magento

    Research Sucuri, 18 Aug 2020

    During a website remediation, we recently discovered a new version of a Magento credit card stealer which sends all compromised data to the malicious domain cdn-filestore[dot]com . My colleague Luke Leal originally wrote about this malwa...

  28. Web Crawler & User Agent Blocking Techniques

    Research Sucuri, 14 Aug 2020

    This is a simple script that allows hackers to block specific crawlers based upon website requests from specific user-agents. This is useful when you don’t want certain traffic from being able to load certain content - usually a phishing...

  29. Smoker Backdoor: Evasion Techniques in Webshell Backdoors

    Research Sucuri, 13 Aug 2020

    “Smoker Backdoor” is a PHP webshell backdoor that uses hexadecimal and decimal obfuscation in conjunction with the PHP function goto to evade detection from malware scanners. The hexadecimal/decimal obfuscation is clear to see when viewi...

  30. String Concatenation: Obfuscation Techniques

    Research Sucuri, 12 Aug 2020

    While string concatenation has many valuable applications in development - such as making code more efficient or functions more effective - it is also a popular way for attackers to obfuscate code and try to make it more difficult to det...

  31. PHP Binary Downloader

    Research Sucuri, 7 Aug 2020

    When possible, an attacker will want to avoid using specific functions in their PHP code that they know are more likely to be flagged by a scanner. Some examples of suspicious functions commonly detected include system and file_put_conte...

  32. PHP Backdoor Obfuscated One Liner

    Research Sucuri, 5 Aug 2020

    In the past, I have explained how small one line PHP backdoors use obfuscation and strings of code in HTTP requests to pass attacker’s commands to backdoors. Today, I’ll highlight another similar injection example and describe some of th...

  33. Vulnerabilities Digest: July 2020

    Research Sucuri, 3 Aug 2020

    Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs Asset CleanUp: Page Speed Authenticated XSS 1.4.6.7 80000 Quiz And Survey Master Authenticated Stored XSS 7.0.0 30000 Comments - wpDiscuz 7.0.0 - Arbitra...

  34. SEO Hacktool: Sitemap Generator

    Research Sucuri, 30 Jul 2020

    An XML sitemap is an important part of a website’s SEO and exists to help search engine crawlers index new URLs on your website. For example, if a site has a large number of pages that were recently updated and the owner wants Google to ...

  35. Reverse String WooCommerce WordPress Credit Card Swiper

    Research Sucuri, 27 Jul 2020

    As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential dread even further. As a sequel to my last blog post earlier this year about the credit card sw...

  36. Skimmers in Images & GitHub Repos

    Research Sucuri, 22 Jul 2020

    MalwareBytes recently shared some information about web skimmers that store malicious code inside real .ico files. During a routine investigation, we detected a similar issue. Instead of targeting .ico files, however, attackers chose to ...

  37. Fake WordPress Plugin SiteSpeed Serves Malicious Ads & Backdoors

    Research Sucuri, 16 Jul 2020

    Fake WordPress plugins appear to be trending as an effective way of establishing a foothold on compromised websites. During a recent investigation, we discovered a fake component which was masquerading as a legitimate plugin. Named SiteS...

  38. Pirated WordPress Plugins Bundled with Backdoors

    Research Sucuri, 8 Jul 2020

    One widespread belief among webmasters is that attackers typically only compromise websites in a couple of ways: by exploiting vulnerabilities or stealing login credentials. Although these are certainly two of the more common attack vect...

  39. Vulnerabilities Digest: June 2020

    Research Sucuri, 6 Jul 2020

    Highlights for June 2020 Cross site scripting is still the most common vulnerability in WordPress Plugins. Bad actors are taking advantage of the lack of restrictions in critical functions and issues surrounding user input data sanitizat...

  40. Sucuri Sit-Down Episode 2: Malware Types Explained with Krasimir Konov

    Research Sucuri, 24 Jun 2020

    Malware comes in many different varieties. Analyst Krasimir Konov is on this month’s Sucuri Sit-Down to help keep them all straight. From malicious iframes to SEO spam, join host Justin Channell as he racks Krasimir’s brain on all the di...

  41. Cross Site Scripting in YITH WooCommerce Ajax Product Filter

    Research Sucuri, 22 Jun 2020

    During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+ users of the YITH WooCommerce Ajax Product Filter plugin. Current State of the Vulnerabi...

  42. Vulnerable Plugins: June 2020 Update

    Research Sucuri, 19 Jun 2020

    This is a mid-month update to our regular Monthly Vulnerability Digest , which reveals a number of new patches for disclosed vulnerabilities. Plugin Vulnerability Patched Version Installs Elementor Page Builder Authenticated Stored XSS 2...

  43. Experience + Technology: How We Clean Infected Websites at Sucuri

    Research Sucuri, 16 Jun 2020

    Our malware removal service is particularly effective because it combines automated and human elements. The process gets off to a quick start thanks to cleanup scripts developed by our threat researchers. Real people also get their hands...

  44. What is the Gibberish Hack?

    Research Sucuri, 12 Jun 2020

    Discovering some random folder with numbers and letters you don’t remember on your website would make any website owner put on their detective cap. At first, you may think, “Did I leave my FTP client open and my cat ran across the keyboa...

  45. What is a Website Defacement?

    Research Sucuri, 9 Jun 2020

    Website defacement is the most obvious sign of a hack. In these cases, bad actors who have gained access to an environment leave their mark through digital vandalism. For website owners, it means trying to access your homepage, only to f...

  46. Evasion Tactics in Hybrid Credit Card Skimmers

    Research Sucuri, 5 Jun 2020

    The most common type of Magento credit card stealing malware is client-side JavaScript that grabs data entered in a checkout form and sends it to a third-party server controlled by the attackers. Though popular with bad actors, one of th...

  47. Labs Notes Monthly Recap - May/2020

    Research Sucuri, 3 Jun 2020

    In 2020, we doubled up our research efforts to report on many new attacks and hacks that we see in the wild. We believe that being informed is a big part of having a good website security posture. Sucuri Labs provides website malware res...

  48. Malicious Curl Downloader

    Research Sucuri, 2 Jun 2020

    If you want to easily download and save remote files, curl is an excellent command-line tool for Windows and Unix. It supports HTTP, HTTPS, and FTP protocols and allows for custom HTTP headers, which makes it a common feature in some of ...

  49. Vulnerabilities Digest: May 2020

    Research Sucuri, 29 May 2020

    Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs WP Product Review Unauthenticated Stored XSS 3.7.6 40000 Form Maker by 10Web Authenticated SQL Injection - 100000 Add-on SweetAlert Contact Form 7 Authen...

  50. Understanding & Stopping Malicious Redirects

    Research Sucuri, 22 May 2020

    Many website owners don’t know they’re infected with malicious redirects until they start getting calls from wary customers. Instead of the site they were expecting, it loaded some pretty shady content from the nether reaches of the inte...

Common types of WordPress compromise

WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.

Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.

Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.

Signs your WordPress site may be hacked

Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.

Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.

Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.

What to do first if you think your WordPress site is hacked

Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.

Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.

The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.

Common questions

Answers to the questions we hear most about this.

How can I tell if my WordPress site has malware?

Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.

Should I delete suspicious files straight away?

Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.

Can restoring a backup fix a hacked WordPress site?

A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.

What should I change after a WordPress hack?

Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.

Think your website has been hacked?

Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.

Get website support