HomeLatest WordPress security threats
Latest WordPress security threats
This page brings together recent WordPress security research and attack reports from Wordfence, Patchstack, Sucuri and WPScan. We summarise the headlines and link to the original vendor research so you can read the source in full.
1,878 reports kept since 2009. Updated automatically every 10 minutes. Last checked 1 min ago.
- Code Comments Reveal SCP 173 Malware
Research Sucuri, 10 Nov 2020
We sometimes find malware code injections that contain strange code comments, which are normally used by programmers to annotate a section of code - for example, a short description of a feature or functionality for other developers to r...
- Legacy Mauthtoken Malware Continues to Redirect Mobile Users
Research Sucuri, 5 Nov 2020
During malware analysis, we regularly find variations of this injected script on various compromised websites: . The variable “ _0x446d ” assigns hex encoded strings in different positions in the array. If we get the ASCII representation...
- CSS-JS Steganography in Fake Flash Player Update Malware
Research Sucuri, 2 Nov 2020
This summer, MalwareBytes researcher Jérôme Segura wrote an article about how criminals use image files (.ico) to hide JavaScript credit card stealers on compromised e-commerce sites. In a tweet, Affable Kraut also reported another simil...
- Reflected XSS in WordPress v5.5.1 and Lower
Research Sucuri, 30 Oct 2020
WordPress released version 5.5.2 yesterday, which fixed a reflected XSS vulnerability we reported earlier this year. The root cause of this issue is a bug in the way WordPress determines a user’s current page, and which may cause a few o...
- Bridging the Gap Between Application and Network Security with CleanBrowsing
Research Sucuri, 30 Oct 2020
When we started Sucuri we set out to make enterprise security accessible, affordable, and effective for every day webmasters. It was at a time when open-source platforms like WordPress, Joomla!, Drupal, and others were changing the web l...
- 5 Places Where You’d Never Expect to Get Hacked
Research Sucuri, 28 Oct 2020
For every gleaming new IoT device that hits the market, a hacker somewhere is figuring out how to compromise it. Today, even routine activities can land you in the sights of a bad actor. Imagine what a bad day could look like in this era...
- R_Evil WordPress Hacktool & Malicious JavaScript Injections
Research Sucuri, 22 Oct 2020
We often see hackers reusing the same malware, with only a few new adjustments to obfuscate the code so that it is more difficult for scanning tools to detect. However, sometimes entirely new attack tools are created and deployed by thre...
- Sucuri Sit-Down Episode 4: XSS & WP Plugin Vulnerabilities with Antony Garand
Research Sucuri, 15 Oct 2020
October is National Cyber Security Awareness Month, and we’re back with analyst Antony Garand to take a deeper look into cross site scripting (XSS) attacks and WordPress plugin vulnerabilities. Plus, host Justin Channell will catch you u...
- Magento Phishing Leverages JavaScript For Exfiltration
Research Sucuri, 14 Oct 2020
During a recent investigation, a Magento admin login phishing page was found on a compromised website using the file name wp-order.php . This is an odd file name choice for a Magento phishing page, but nevertheless it successfully loads ...
- Redirects to YouTube Defacement Channel
Research Sucuri, 13 Oct 2020
During a recent investigation, we found an infected website was redirecting to YouTube after its main index.php file had been modified to include the following line of HTML: This technique works because it’s possible to use HTML within ....
- Backdoor Shell Dropper Deploys CMS-Specific Malware
Research Sucuri, 6 Oct 2020
A large majority of the malware we find on compromised websites are backdoors that allow an attacker to maintain unauthorized access to the site and execute whatever commands they want. Another common scenario includes malware which is d...
- GFX Xsender Hack Tool: A Spam Mailer
Research Sucuri, 1 Oct 2020
PHP hack tools are created and used by attackers to help automate frequent or tedious tasks. During a recent investigation, we came across a hack tool used to simplify the process of sending predefined HTML emails to a list of email addr...
- Malicious Pop-up Redirects Baidu Traffic
Research Sucuri, 29 Sep 2020
Malicious pop-ups and redirects have become two extremely common techniques used by attackers to drive traffic wherever they want. \ During a recent investigation, we came across an obfuscated pop-up script leveraging baidu[.]com search ...
- Backdoor Obfuscation: tempnam & URL Encoding
Research Sucuri, 28 Sep 2020
In an attempt to avoid detection, attackers and malware authors are always experimenting with different methods to obfuscate their malicious code. During a recent investigation, we came across an interesting backdoor that was leveraging ...
- Magento Credit Card Stealing Malware: gstaticapi
Research Sucuri, 25 Sep 2020
Our team recently came across a malicious script used on a Magento website titled gstaticapi, which targeted checkout processes to capture and exfiltrate stolen information. To obtain sensitive details, the malware loads external javascr...
- Malicious One-Liner Using Hastebin
Research Sucuri, 23 Sep 2020
Short scripts that deliver malware to a website are nothing new, but during a recent investigation we found a script using hastebin[.]com , which is a domain we see used infrequently. The script was found writing malicious contents into ...
- The Hidden PHP Malware that Reinfects Cleaned Files
Research Sucuri, 18 Sep 2020
Website reinfections are a serious problem for website owners, and it can often be difficult to determine the cause behind the reinfection - especially if you lack access to necessary logs, which is usually the case for shared hosting se...
- phpbash - A Terminal Emulator Web Shell
Research Sucuri, 16 Sep 2020
It’s common for hackers to utilize post-compromise tools that contain a graphical user interface (GUI) that can be loaded in the web browser. A GUI generally makes the tool easier to use - and certainly more visually appealing than just ...
- WordPress Malware Disables Security Plugins to Avoid Detection
Research Sucuri, 10 Sep 2020
An alarm or monitoring system is a great tool that can be used to improve the security of a home or website, but what if an attacker can easily disable it? I’ve previously written about malware that reverses security hardening measures e...
- Reflected XSS in WordPress Plugin Admin Pages
Research Sucuri, 8 Sep 2020
The administrative dashboard in WordPress is a pretty safe place: Only elevated users can access it. Exploiting a plugin’s admin panel would serve very little purpose here - an administrator already has the required permissions to do all...
- Insufficient Privilege Validation in NextScripts: Social Networks Auto-Poster
Research Sucuri, 4 Sep 2020
NextScripts: Social Networks Auto-Poster is a plugin that automatically publishes posts from your blog to your Social Media accounts such as Facebook, Twitter, Google+, Blogger, Tumblr, Flickr, LinkedIn, Instagram, Telegram, YouTube, Wor...
- Critical Vulnerability in File Manager Plugin Affecting 700k WordPress Websites
Research Sucuri, 2 Sep 2020
Yesterday, the WordPress plugin File Manager was updated, fixing a critical vulnerability allowing any website visitor to gain complete access to the website. Users of our WAF were never vulnerable to this exploit. The Sucuri firewall bl...
- Using assert() to Execute Malware in PHP 7 Environments
Research Sucuri, 1 Sep 2020
Initially released December 2015, PHP 7 introduced a multitude of performance and security improvements. Approximately 43.7% of websites across the web currently use PHP 7.x, making it an incredibly popular scripting language - which is ...
- Persistent WordPress User Injection
Research Sucuri, 28 Aug 2020
Our team recently stumbled across an interesting example of malicious code used to add an arbitrary user inside WordPress. The following code was detected at the bottom of the theme’s functions.php. I t uses internal WordPress functions ...
- Magento Multiversion (1.x/2.x) Backdoor
Research Sucuri, 26 Aug 2020
The Magento 1 EOL date has already passed, however it’s evident that a large number of websites will continue to use it for the foreseeable future. Unfortunately, attackers are also aware that many websites are struggling with their Mage...
- Multiple Vulnerabilities In Discount Rules for WooCommerce Plugin
Research Patchstack, 20 Aug 2020
There are SQLi and unauthenticated stored XSS vulnerabilities in Discount Rules for the WooCommerce WordPress plugin. The Discount Rules for the WooCommerce plugin (versions 2.0.2 and below) suffer from multiple vulnerabilities such as S...
- CDN-Filestore Credit Card Stealer for Magento
Research Sucuri, 18 Aug 2020
During a website remediation, we recently discovered a new version of a Magento credit card stealer which sends all compromised data to the malicious domain cdn-filestore[dot]com . My colleague Luke Leal originally wrote about this malwa...
- Web Crawler & User Agent Blocking Techniques
Research Sucuri, 14 Aug 2020
This is a simple script that allows hackers to block specific crawlers based upon website requests from specific user-agents. This is useful when you don’t want certain traffic from being able to load certain content - usually a phishing...
- Smoker Backdoor: Evasion Techniques in Webshell Backdoors
Research Sucuri, 13 Aug 2020
“Smoker Backdoor” is a PHP webshell backdoor that uses hexadecimal and decimal obfuscation in conjunction with the PHP function goto to evade detection from malware scanners. The hexadecimal/decimal obfuscation is clear to see when viewi...
- String Concatenation: Obfuscation Techniques
Research Sucuri, 12 Aug 2020
While string concatenation has many valuable applications in development - such as making code more efficient or functions more effective - it is also a popular way for attackers to obfuscate code and try to make it more difficult to det...
- PHP Binary Downloader
Research Sucuri, 7 Aug 2020
When possible, an attacker will want to avoid using specific functions in their PHP code that they know are more likely to be flagged by a scanner. Some examples of suspicious functions commonly detected include system and file_put_conte...
- PHP Backdoor Obfuscated One Liner
Research Sucuri, 5 Aug 2020
In the past, I have explained how small one line PHP backdoors use obfuscation and strings of code in HTTP requests to pass attacker’s commands to backdoors. Today, I’ll highlight another similar injection example and describe some of th...
- Vulnerabilities Digest: July 2020
Research Sucuri, 3 Aug 2020
Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs Asset CleanUp: Page Speed Authenticated XSS 1.4.6.7 80000 Quiz And Survey Master Authenticated Stored XSS 7.0.0 30000 Comments - wpDiscuz 7.0.0 - Arbitra...
- SEO Hacktool: Sitemap Generator
Research Sucuri, 30 Jul 2020
An XML sitemap is an important part of a website’s SEO and exists to help search engine crawlers index new URLs on your website. For example, if a site has a large number of pages that were recently updated and the owner wants Google to ...
- Reverse String WooCommerce WordPress Credit Card Swiper
Research Sucuri, 27 Jul 2020
As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential dread even further. As a sequel to my last blog post earlier this year about the credit card sw...
- Skimmers in Images & GitHub Repos
Research Sucuri, 22 Jul 2020
MalwareBytes recently shared some information about web skimmers that store malicious code inside real .ico files. During a routine investigation, we detected a similar issue. Instead of targeting .ico files, however, attackers chose to ...
- Fake WordPress Plugin SiteSpeed Serves Malicious Ads & Backdoors
Research Sucuri, 16 Jul 2020
Fake WordPress plugins appear to be trending as an effective way of establishing a foothold on compromised websites. During a recent investigation, we discovered a fake component which was masquerading as a legitimate plugin. Named SiteS...
- Pirated WordPress Plugins Bundled with Backdoors
Research Sucuri, 8 Jul 2020
One widespread belief among webmasters is that attackers typically only compromise websites in a couple of ways: by exploiting vulnerabilities or stealing login credentials. Although these are certainly two of the more common attack vect...
- Vulnerabilities Digest: June 2020
Research Sucuri, 6 Jul 2020
Highlights for June 2020 Cross site scripting is still the most common vulnerability in WordPress Plugins. Bad actors are taking advantage of the lack of restrictions in critical functions and issues surrounding user input data sanitizat...
- Sucuri Sit-Down Episode 2: Malware Types Explained with Krasimir Konov
Research Sucuri, 24 Jun 2020
Malware comes in many different varieties. Analyst Krasimir Konov is on this month’s Sucuri Sit-Down to help keep them all straight. From malicious iframes to SEO spam, join host Justin Channell as he racks Krasimir’s brain on all the di...
- Cross Site Scripting in YITH WooCommerce Ajax Product Filter
Research Sucuri, 22 Jun 2020
During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+ users of the YITH WooCommerce Ajax Product Filter plugin. Current State of the Vulnerabi...
- Vulnerable Plugins: June 2020 Update
Research Sucuri, 19 Jun 2020
This is a mid-month update to our regular Monthly Vulnerability Digest , which reveals a number of new patches for disclosed vulnerabilities. Plugin Vulnerability Patched Version Installs Elementor Page Builder Authenticated Stored XSS 2...
- Experience + Technology: How We Clean Infected Websites at Sucuri
Research Sucuri, 16 Jun 2020
Our malware removal service is particularly effective because it combines automated and human elements. The process gets off to a quick start thanks to cleanup scripts developed by our threat researchers. Real people also get their hands...
- What is the Gibberish Hack?
Research Sucuri, 12 Jun 2020
Discovering some random folder with numbers and letters you don’t remember on your website would make any website owner put on their detective cap. At first, you may think, “Did I leave my FTP client open and my cat ran across the keyboa...
- What is a Website Defacement?
Research Sucuri, 9 Jun 2020
Website defacement is the most obvious sign of a hack. In these cases, bad actors who have gained access to an environment leave their mark through digital vandalism. For website owners, it means trying to access your homepage, only to f...
- Evasion Tactics in Hybrid Credit Card Skimmers
Research Sucuri, 5 Jun 2020
The most common type of Magento credit card stealing malware is client-side JavaScript that grabs data entered in a checkout form and sends it to a third-party server controlled by the attackers. Though popular with bad actors, one of th...
- Labs Notes Monthly Recap - May/2020
Research Sucuri, 3 Jun 2020
In 2020, we doubled up our research efforts to report on many new attacks and hacks that we see in the wild. We believe that being informed is a big part of having a good website security posture. Sucuri Labs provides website malware res...
- Malicious Curl Downloader
Research Sucuri, 2 Jun 2020
If you want to easily download and save remote files, curl is an excellent command-line tool for Windows and Unix. It supports HTTP, HTTPS, and FTP protocols and allows for custom HTTP headers, which makes it a common feature in some of ...
- Vulnerabilities Digest: May 2020
Research Sucuri, 29 May 2020
Relevant Plugins and Vulnerabilities: Plugin Vulnerability Patched Version Installs WP Product Review Unauthenticated Stored XSS 3.7.6 40000 Form Maker by 10Web Authenticated SQL Injection - 100000 Add-on SweetAlert Contact Form 7 Authen...
- Understanding & Stopping Malicious Redirects
Research Sucuri, 22 May 2020
Many website owners don’t know they’re infected with malicious redirects until they start getting calls from wary customers. Instead of the site they were expecting, it loaded some pretty shady content from the nether reaches of the inte...
Common types of WordPress compromise
WordPress compromises do not all look the same. Some are obvious to visitors, while others are designed to remain unnoticed. A site may start sending visitors to an unrelated domain, display pages or links that the owner never created, or contain a backdoor that allows an attacker to return after the visible problem has been removed.
Other compromises can involve rogue administrator accounts or fake plugins placed in the WordPress installation to blend in with legitimate software. On WooCommerce sites, malicious code may target the checkout process or other pages that handle customer data. The presence of unfamiliar code is not enough on its own to identify what happened, so the investigation needs to establish what changed, when it changed and how the attacker gained access.
Outdated components are one possible route, but compromised passwords, exposed hosting credentials and other weaknesses can also matter. WordPress recommends keeping software current, using strong passwords, controlling file permissions and maintaining reliable backups as part of normal hardening.
Signs your WordPress site may be hacked
Unexpected redirects are a common warning sign, particularly when they appear only on certain devices, browsers or traffic sources. Other clues include unfamiliar administrator users, pages you did not publish, altered titles or search snippets, unexplained file changes, new scheduled tasks, or security warnings in Google Search Console.
Performance problems can also justify investigation, but a slow site does not automatically mean malware. The same applies to unusual server load or email activity. Treat these as signals to inspect logs, files, users and recent changes rather than proof of a specific infection.
Google recommends using the Security Issues report in Search Console when hacked content or malware is suspected. A simple site search can also reveal indexed pages that do not belong to you. If you find something unexpected, record it before making changes so you have evidence to compare during cleanup.
What to do first if you think your WordPress site is hacked
Do not begin by deleting every suspicious file you can see. First take a copy of the affected site and database, note the time the problem was found and preserve relevant logs where available. This gives you something to examine if the visible symptoms return or if you need to identify the original entry point.
Change passwords for WordPress administrators, hosting, SFTP or FTP, the database and other privileged services that could have been exposed. Review all administrator accounts and remove access you do not recognise. Then decide whether the safest recovery route is a clean restoration from a known good backup or a controlled malware cleanup.
The job is not finished when the unwanted page or redirect disappears. Check themes, plugins, WordPress core, configuration files and scheduled tasks for persistence, update vulnerable components and close the route that allowed access. If Google has flagged the site, follow its hacked site guidance and request review only after the site has been cleaned. Our WordPress malware removal page explains the recovery service. Hacked Site Rescue is £249 fixed price.
Common questions
Answers to the questions we hear most about this.
How can I tell if my WordPress site has malware?
Look for unexpected redirects, unfamiliar administrator accounts, pages or links you did not create, unexplained file changes and security warnings in Google Search Console. None of these signs identifies the cause by itself, so the site still needs investigation.
Should I delete suspicious files straight away?
Not necessarily. Take a copy of the site and database first and preserve useful logs where possible. Deleting visible files before recording the incident can remove evidence without closing the route used to gain access.
Can restoring a backup fix a hacked WordPress site?
A clean backup can be an effective recovery route if it predates the compromise, but you still need to identify and fix the entry point. Otherwise the same weakness can remain after the restore.
What should I change after a WordPress hack?
Change privileged passwords, review administrator users, update vulnerable software and inspect the site for persistence such as backdoors or altered scheduled tasks. The exact steps depend on how the compromise occurred.
Think your website has been hacked?
Call us or send the details. Hacked Site Rescue is a fixed £249, and we find how the attacker got in.